Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 23 Jul 2015 10:38:30 +0300
From:      Alexandr Krivulya <shuriku@shurik.kiev.ua>
To:        FreeBSD CURRENT <freebsd-current@freebsd.org>
Subject:   IPSEC stop works after r285336
Message-ID:  <55B099F6.8000004@shurik.kiev.ua>

next in thread | raw e-mail | index | archive | help
I have IPSEC tunnel inside l2tp tunnel via mpd. After r285536 I see only
outgoing esp packets on ng interface:

root@thinkpad:/usr/src # tcpdump -i ng0
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on ng0, link-type NULL (BSD loopback), capture size 262144 bytes
10:35:27.331886 IP 10.10.10.2 > 10.10.10.1:
ESP(spi=0x03081e58,seq=0x9a5), length 140
10:35:28.371707 IP 10.10.10.2 > 10.10.10.1:
ESP(spi=0x03081e58,seq=0x9a6), length 140
10:35:29.443536 IP 10.10.10.2 > 10.10.10.1:
ESP(spi=0x03081e58,seq=0x9a7), length 140
10:35:30.457370 IP 10.10.10.2 > 10.10.10.1:
ESP(spi=0x03081e58,seq=0x9a8), length 140
10:35:31.475606 IP 10.10.10.2 > 10.10.10.1:
ESP(spi=0x03081e58,seq=0x9a9), length 140
10:35:31.622315 IP 10.10.10.1.isakmp > 10.10.10.2.isakmp: isakmp: phase
2/others ? inf[E]
10:35:31.622544 IP 10.10.10.2.isakmp > 10.10.10.1.isakmp: isakmp: phase
2/others ? inf[E]
10:35:31.622658 IP 10.10.10.2.isakmp > 10.10.10.1.isakmp: isakmp: phase
2/others ? inf[E]
10:35:31.623933 IP 10.10.10.1.isakmp > 10.10.10.2.isakmp: isakmp: phase
2/others ? inf[E]
10:35:32.492349 IP 10.10.10.2 > 10.10.10.1:
ESP(spi=0x03081e58,seq=0x9aa), length 140
10:35:33.509346 IP 10.10.10.2 > 10.10.10.1:
ESP(spi=0x03081e58,seq=0x9ab), length 140
10:35:34.527187 IP 10.10.10.2 > 10.10.10.1:
ESP(spi=0x03081e58,seq=0x9ac), length 140
10:35:35.539600 IP 10.10.10.2 > 10.10.10.1:
ESP(spi=0x03081e58,seq=0x9ad), length 140

With r285535 all works fine.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?55B099F6.8000004>