RE: Looking for info on ipsec passthrough (or passthru?)

Ok, I looked it up and think I know what "passthru" is.

Getting IPsec through NAT is a VERY hard problem.  There isn't an easy way
of associating (on the wire) that a packet with an SPI of this value needs
to be demultiplexed to this destination because a packet with another SPI
went through the NAT gateway...

Passthru is one way of solving this, basically saying all IPsec traffic
flows through the NAT to this 1 destination.

Passthru is a hack until something like RSIP becomes a reality.


