I've noticed there's a problem with establishing a Roadwarrior CA connection with a partner that is behind NAT. ASL [5.014] always rejects the connection, saying there's no connection known for the IP address the client has behind the NAT. Setting the Virtual IP address for the Remote Key as specified in the help does not work. However, it does work with a simple Roadwarrior connection.
After looking at the differences between the entries in the ipsec.conf for the CA and the simple connection, the reason becomes apparent: ASL does not include the Virtual IPs of the Remote Keys in the CA connection - which is somewhat correct because it couldn't distinguish the IPs of UserA and UserB in the CA connection. However this makes it impossible to use a CA connection with clients behind NAT (at least without having to mess with the ipsec.conf. My current workaround is to include a range of Virtual IPs in the %default section
).I suggest to provide the ability to add Virtual IPs when editing a CA connection in the WebAdmin. Otherwise I don't see a possibility to get this to work with NAT clients, unless I'm missing something fundamental. In this case, I'd appreciate any hint how to do it correctly then

Sascha
This thread was automatically locked due to age.
.