|
A
little more detail on this:
You
CAN use NAT on encrypted packets using FWZ, SKIP, and IKE with AH only (no ESP;
see below) since the packets are not encapsulated - the original header will be
translated. You can also use NAT on IKE packets using ESP for
encapsulation, but the NAT will apply prior to the
encryption/encapsulation. This allows you to do things like create NAT
rules to pass traffic over a VPN to sites with the same addressing on both
ends.
Not
sure if this answers Aylton's original question, but hopefully worth at least
$0.02.
Dan Hitchcock
|
- [FW1] Some packets do not get NATted. Have you seen th... Aylton Souza, CISSP
- Re: [FW1] Some packets do not get NATted. Have yo... Tim Holman
- Re: [FW1] Some packets do not get NATted. Have yo... Daniel Hitchcock
- Re: [FW1] Some packets do not get NATted. Have yo... Aylton Souza, CISSP
- RE: [FW1] Some packets do not get NATted. Have yo... Aho,Paul(NXI)
