Security Basics mailing list archives

Re: IPSec Problem over Router


From: Rodney Green <rgreen () cinchhost com>
Date: Thu, 25 Sep 2003 15:20:33 -0400

red temptation wrote:

hi,

we have a Problem concerning IPSec. We want to create
a tunnel from a WinXP Laptop (located on the Internet
with an official IP), to a private Network (using
NAT). For authentication purpose we use certificates.

It's no problem to open Port 500 on our current
Network-Router, but Protocol 50 and 51 are not
supported while using NAT. That's why we are not able
to establish an IPSec tunnel with that router.

Can anyone suggest a low cost Router with the ability
to store certificates and enable us to establish the
tunnel. It should have an included firewall.

What router do you have? IP 50 should work with NAT because the IP header is not included in the authenticated data so it's passed through NAT without problems.

---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: