[strongSwan] VPN and NAT

Naveen Neelakanta nbnopenswan at gmail.com
Fri Sep 20 01:08:35 CEST 2013

Hello ,
Can IPsec VPN and NAT be on the same device .
Should NAT be by passed if we have ipsec vpn enabled.

Just wanted to know if a router acts has a client and strongswan
is used has server, strongswan assigns a virtual ip . In this case
all the lan ip behind the router need to be source natted to virtual Ip
assigned my strongswan and then ipsec is applied to the lan packets
and sent with routers public ip.

Please correct me if my Understanding is correct.

