Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 26 Jun 2008 12:05:08 -0500
From:      mgrooms <mgrooms@shrew.net>
To:        vanhu_bsd@zeninc.net
Cc:        freebsd-net@freebsd.org, harunaga@harunaga.ru
Subject:   Re: patch for IPSEC_NAT_T
Message-ID:  <30025d295f8077e96bcb3f3a076c8bd1@localhost>
In-Reply-To: <d9bbe0c97e56991023408e1e97d8d0f6@localhost>
References:  <d9bbe0c97e56991023408e1e97d8d0f6@localhost>

next in thread | previous in thread | raw e-mail | index | archive | help

On Thu, 26 Jun 2008 11:51:26 -0500, mgrooms <mgrooms@shrew.net> wrote:
> 
> ESP transport with NAT-T may need NAT-OA support, which is not
> provided by the actual patch, nor by userland.
> 

I checked in Timos patch for NAT-T original address support into
ipsec-tools last December. This will be available in our 0.8 release.

http://cvsweb.netbsd.org/bsdweb.cgi/src/crypto/dist/ipsec-tools/ChangeLog.diff?r1=1.139&r2=1.140

I believe we are just missing the kernel bits on FreeBSD.

-Matthew




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?30025d295f8077e96bcb3f3a076c8bd1>