Ben,

> I suspect you're screwed. Just for a start, a one-to-many NAT
> implementation is never going to work. In brief, dynamic NAT keeps track
> of all the different connections based on TCP/UDP port multiplexing.
> Dynamic NAT has no way of coping with IP protocols like ESP and AH that
> contain no port data. 

        It's strange, because from the docs of SP2 it's supposed to work,
even with hide NAT... anyway, if I get around it I'll tell the list about
it. 

        Regards,

-- p.

-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to