Date: Sun, 20 Apr 2003 10:20:53 -0700 From: Lars Eggert <larse@ISI.EDU> To: "Jacques A. Vidrine" <nectar@FreeBSD.org> Cc: "Crist J. Clark" <cjc@FreeBSD.org> Subject: Re: Single IP host and IPsec tunnel mode experience Message-ID: <3EA2D6F5.4060209@isi.edu> In-Reply-To: <20030420165538.GA31101@madman.celabo.org> References: <20030410161511.GA25681@madman.celabo.org> <20030416052335.GA2519@blossom.cjclark.org> <20030416123621.GC72501@madman.celabo.org> <20030420165538.GA31101@madman.celabo.org>
next in thread | previous in thread | raw e-mail | index | archive | help
[-- Attachment #1 --]
On 4/20/2003 9:55 AM, Jacques A. Vidrine wrote:
> On Wed, Apr 16, 2003 at 07:36:21AM -0500, Jacques A. Vidrine wrote:
>
>>On Tue, Apr 15, 2003 at 10:23:35PM -0700, Crist J. Clark wrote:
>>
>>>'uname -a'?
>>
>>The endpoints were both 4.7.
>>
>>
>>>I can't reproduce this on a 4.8 to 4.7 tunnel. On
>>>192.168.64.70,
>>>
>>> spdadd 192.168.64.70/32 10.0.0.0/24 any -P out
>>> ipsec esp/tunnel/192.168.64.70-192.168.64.20/require;
>>> spdadd 10.0.0.0/24 192.168.64.70/32 any -P in
>>> ipsec esp/tunnel/192.168.64.20-192.168.64.70/require;
>>>
>>>And on 192.168.64.20, the gateway to 10.0.0.0/24,
>>>
>>> spdadd 192.168.64.70/32 10.0.0.0/24 any -P in
>>> ipsec esp/tunnel/192.168.64.70-192.168.64.20/require;
>>> spdadd 10.0.0.0/24 192.168.64.70/32 any -P out
>>> ipsec esp/tunnel/192.168.64.20-192.168.64.70/require;
>>>
>>>Works fine.
>>
>>Hmm, yes, that appears to be exactly what I'm trying to do. Well,
>>that's heartening ... it means that there is likely some anomoly in my
>>environment that is hosing me. Now if only I can figure what it is :-)
>
>
> Oddly enough ... ESP works, AH does not.
Are you going through a NAT box? (Sorry, haven't been following this
thread closely.) AH includes more of the IP header when computing the
crypto checksum (compared to ESP), if those fields get diddled by a NAT
box, the receiver will drop the packets because of bad crypto. One of
the netstat counters on the receiver will show this.
If you need to authenticate, maybe try using ESP authentication?
Lars
--
Lars Eggert <larse@isi.edu> USC Information Sciences Institute
[-- Attachment #2 --]
0 *H
010 + 0 *H
080fErtcvE.0
*H
010 UZA10UWestern Cape10U Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0) *H
personal-freemail@thawte.com0
000830000000Z
040827235959Z010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
*H
0 32c %E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf - ki N0L0)U"0 010UPrivateLabel1-2970U0 0U0
*H
1KG]qSl]y=&b""I'{9$
*8PUl
LGlX1B li+@]jy.%݊
Z<D&iHΥbb090%A0
*H
010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
020824185339Z
030824185339Z0T10
UEggert1
0U*Lars10ULars Eggert10 *H
larse@isi.edu0"0
*H
0
6Fxΰ7aED&0+Dj)ֽXCUcnleijmz~S0J jWV~ 1^({IݛLjӖ
ao:bP}WLVܱ욗cDɖ_Kv.A(W49;Z8-uXE
6b
@_0%#d`Rto5 L0R`w@7
r Hcc U3%7N_o V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U0 0
*H
]Ȕ,fK<cjRZeLan@Z6,=
fK?yO#8+ Ni*LSfpQg<(aӒ$kTx_AL1>ގ|S090%A0
*H
010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
020824185339Z
030824185339Z0T10
UEggert1
0U*Lars10ULars Eggert10 *H
larse@isi.edu0"0
*H
0
6Fxΰ7aED&0+Dj)ֽXCUcnleijmz~S0J jWV~ 1^({IݛLjӖ
ao:bP}WLVܱ욗cDɖ_Kv.A(W49;Z8-uXE
6b
@_0%#d`Rto5 L0R`w@7
r Hcc U3%7N_o V0T0*+e!0 00L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U0 0
*H
]Ȕ,fK<cjRZeLan@Z6,=
fK?yO#8+ Ni*LSfpQg<(aӒ$kTx_AL1>ގ|S100010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0 + 0 *H
1 *H
0 *H
1
030420172053Z0# *H
1<Z܊]eSG/0R *H
1E0C0
*H
0*H
0
*H
@0+0
*H
(0 +710010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0*H
1010 UZA10UWestern Cape10U Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0
*H
:'ӧFЊݫfx]M-*8Xw̠CؚܔٷIĨ]
.+dٰ> \VETys ;}7Jjv^~Xr߫Z_렒ߵRWlyckj2HfM4=3k
^SUJ2ؔ:˓ ˸Ν!3E:qn)V}TlpLFr>~U'n8:#`C{
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3EA2D6F5.4060209>
