ip_output: NAT then IPSEC

Eugene Grosbein egrosbein at rdtc.ru
Thu Jun 14 16:42:47 UTC 2012


Hi!

How do I make FreeBSD 8-based router/NAT/security gateway
first perform NAT for outgoing packets then apply IPSEC transport mode
for plain TCP traffic?

Presently, locally originated packets are encrypted just fine
but routed and NAT-ed packet go out unencrypted.

I use ipfw nat.

Eugene Grosbein


More information about the freebsd-net mailing list