Brian A. Seklecki lavalamp at spiritual-machines.org
Fri May 4 11:47:59 EDT 2007

Right; and for some reason, the FreeBSD 6.x NAT-T bug hasn't been applied 
to the tree; it's just floating out there.

It works fine on NetBSD though.


 	-lava (Brian A. Seklecki - Pittsburgh, PA, USA)
>>>>> "bas" == Brian A Seklecki <lavalamp at spiritual-machines.org> writes:

   bas> racoon(8) and ipsec-tools support NAT-T; it's in the 0.7x
   bas> code.  --enable--natt i believe is the compile-time flag.  UDP
   bas> is definately supported; haven't tried TCP yet.

but kernel support is required, too.  and there are a disgustingly
stupid number of variations on something so simple as NAT-T so that
stacks often don't interoperate.  so I was wondering with what client
and with which BSD.

the ``works, but only for one road warrior behind a NAT'' problem
David mentioned used to be common, too.
