[Openstack] Reg. NAT

Vikram Chhibber vikram.chhibber at gmail.com
Mon Mar 20 21:39:47 UTC 2017

Hi All,

We are using Openstack Kilo release 1:2015.1.4-0ubuntu2. We are trying to
establish transport mode IPSec with one of the VM from outside.

We have a floating IP from 172.17/16 network assigned to this VM that has
private IP from 10.0/16 network.

The IPSec is failing and we are suspecting that the NAT is the culprit. The
sender is computing transport header checksum using 172.17.x.y destination
but the openstack is changing it to 10.0.x.y network and the checksum is

In this release of Openstack, is there a way to disable this nating or any
workarounds? Sender side, we cannot disable the checksum.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openstack.org/pipermail/openstack/attachments/20170320/160cbfa0/attachment.html>

More information about the Openstack mailing list