Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 13 Aug 2002 16:57:52 -0700
From:      Lars Eggert <larse@ISI.EDU>
To:        Terry Lambert <tlambert2@mindspring.com>
Cc:        Les Biffle <les@safety.net>, hackers@freebsd.org
Subject:   Re: IP routing question
Message-ID:  <3D599D00.8070807@isi.edu>
References:  <200208131813.g7DIDiH14643@ns3.safety.net> <3D599416.5CDE92D9@mindspring.com> <3D599679.5090507@isi.edu> <3D599992.7C954D42@mindspring.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Terry Lambert wrote:
> Lars Eggert wrote:
> 
>>I don't think we have the same definition of "the IPSec tunnel problem."
>>Mine is "tunnel mode SAs aren't interfaces, and IPsec duplicates
>>encapsulation and firewalling techniques that are (better) handled
>>outside IPsec", see draft-touch-ipsec-vpn.
>>
>>Having or not having a default route won't matter, since you'll have
>>more specific routes that match before the default route would be picked.
> 
> 
> As you say, SA's are not interfaces.  Try pinging over the link
> from hosts on either side of the tunnel, e.g.:
> 
> 10.0.1.15/8<--->10.0.1.1/8		10.0.2.1/8<---->10.0.2.11/8
> 		public IP #1<----------->public IP #2
> 
> Ping #1    <---------------------------->		works
> Ping #2    <------------------------------------------->broken
> 
> Get rid of the default route, and ping #2 starts working.

That looks like a routing issue on the tunnel endpoint that's 
independent from IPsec - what's in the routing table?

Lars
-- 
Lars Eggert <larse@isi.edu>           USC Information Sciences Institute

[-- Attachment #2 --]
0	*H
010	+0	*H
00G0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
010824164000Z
020824164000Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu00
	*H
0|\Pw v~~FDooӦA\-	 Cˀ4.)&{肋,z(ܷر߈T7_'txGH^tt/ҹB8%t<#ֲNV0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
aJPMՒ]cѭC+kS+wZ1gY",YT41
j6:~℩D~Kؚ‡l=u(ՎM?cF7@}T00G0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
010824164000Z
020824164000Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu00
	*H
0|\Pw v~~FDooӦA\-	 Cˀ4.)&{肋,z(ܷر߈T7_'txGH^tt/ҹB8%t<#ֲNV0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
aJPMՒ]cѭC+kS+wZ1gY",YT41
j6:~℩D~Kؚ‡l=u(ՎM?cF7@}T080fErtcvE.0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
000830000000Z
040827235959Z010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
	*H
032c	%E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf-	kiN0L0)U"0 010UPrivateLabel1-2970U00U0
	*H
1KG]qSl]y=&b""I'{9$
*8PUl
LGlX1B	li+@]jy.%݊
Z<D&iHΥbb100010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30G0	+a0	*H
	1	*H
0	*H
	1
020813235752Z0#	*H
	18Aia70=i%r0R	*H
	1E0C0
*H
0*H
0
*H
@0+0
*H
(0*H
	1010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30G0
	*H
3cs-6P)Z?5XLz3l4ZBf`ИJ?f)	$#sz܅lc}R8<'|6R>c.߄

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3D599D00.8070807>