Date: Tue, 13 Aug 2002 16:57:52 -0700 From: Lars Eggert <larse@ISI.EDU> To: Terry Lambert <tlambert2@mindspring.com> Cc: Les Biffle <les@safety.net>, hackers@freebsd.org Subject: Re: IP routing question Message-ID: <3D599D00.8070807@isi.edu> References: <200208131813.g7DIDiH14643@ns3.safety.net> <3D599416.5CDE92D9@mindspring.com> <3D599679.5090507@isi.edu> <3D599992.7C954D42@mindspring.com>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --]
Terry Lambert wrote:
> Lars Eggert wrote:
>
>>I don't think we have the same definition of "the IPSec tunnel problem."
>>Mine is "tunnel mode SAs aren't interfaces, and IPsec duplicates
>>encapsulation and firewalling techniques that are (better) handled
>>outside IPsec", see draft-touch-ipsec-vpn.
>>
>>Having or not having a default route won't matter, since you'll have
>>more specific routes that match before the default route would be picked.
>
>
> As you say, SA's are not interfaces. Try pinging over the link
> from hosts on either side of the tunnel, e.g.:
>
> 10.0.1.15/8<--->10.0.1.1/8 10.0.2.1/8<---->10.0.2.11/8
> public IP #1<----------->public IP #2
>
> Ping #1 <----------------------------> works
> Ping #2 <------------------------------------------->broken
>
> Get rid of the default route, and ping #2 starts working.
That looks like a routing issue on the tunnel endpoint that's
independent from IPsec - what's in the routing table?
Lars
--
Lars Eggert <larse@isi.edu> USC Information Sciences Institute
[-- Attachment #2 --]
0 *H
010 + 0 *H
00G0
*H
010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
010824164000Z
020824164000Z0T10
UEggert1
0U*Lars10ULars Eggert10 *H
larse@isi.edu00
*H
0 |\Pw v~~FDooӦA\- Cˀ4.)&{肋,z(ܷر߈T7_'txGH^tt/ҹB8%t<#ֲN V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U0 0
*H
aJPMՒ ]cѭC+kS+wZ1gY",YT41
j6:~℩D~Kؚl=u(ՎM?cF7@}T00G0
*H
010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
010824164000Z
020824164000Z0T10
UEggert1
0U*Lars10ULars Eggert10 *H
larse@isi.edu00
*H
0 |\Pw v~~FDooӦA\- Cˀ4.)&{肋,z(ܷر߈T7_'txGH^tt/ҹB8%t<#ֲN V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U0 0
*H
aJPMՒ ]cѭC+kS+wZ1gY",YT41
j6:~℩D~Kؚl=u(ՎM?cF7@}T080fErtcvE.0
*H
010 UZA10UWestern Cape10U Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H
personal-freemail@thawte.com0
000830000000Z
040827235959Z010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
*H
0 32c %E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf - ki N0L0)U"0 010UPrivateLabel1-2970U0 0U0
*H
1KG]qSl]y=&b""I'{9$
*8PUl
LGlX1B li+@]jy.%݊
Z<D&iHΥbb100010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30G0 + a0 *H
1 *H
0 *H
1
020813235752Z0# *H
18Aia70=i%r0R *H
1E0C0
*H
0*H
0
*H
@0+0
*H
(0*H
1010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30G0
*H
3cs-6P)Z?5XLz3l4ZBf`ИJ?f) $#sz܅lc}R8<'|6R>c.߄
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3D599D00.8070807>
