Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not "seriously" interacted, but I have VPN server and I'm using it on all devices in my hope (laptop, PC, phone) which are behind WiFi NAT. They work just fine. I'm using strongswan and IKEv2 on server.


Your NAT behaves and likely has (working) IPSEC ALG stuff, plenty of setups don't.


More likely is that both ends are using IPSec NAT-T (https://tools.ietf.org/html/rfc3947), which has been widely supported for some time. NAT-T encapsulates IP packets inside UDP, with the IKE daemons (usually) as the UDP endpoints.


NAT-T is unfortunately not very reliable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: