From owner-freebsd-hackers@FreeBSD.ORG Tue Apr 6 08:21:11 2004 Return-Path: Delivered-To: freebsd-hackers@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 2EBB516A4CE; Tue, 6 Apr 2004 08:21:11 -0700 (PDT) Received: from tachyon.jinmei.org (kame207.kame.net [203.178.141.207]) by mx1.FreeBSD.org (Postfix) with ESMTP id 591EA43D48; Tue, 6 Apr 2004 08:21:10 -0700 (PDT) (envelope-from jinmei@isl.rdc.toshiba.co.jp) Received: from ocean.jinmei.org (unknown [2001:200:0:4819:64a9:7819:e195:d1b1]) by tachyon.jinmei.org (Postfix) with ESMTP id 9C31F35135; Wed, 7 Apr 2004 00:20:35 +0900 (JST) Date: Wed, 07 Apr 2004 00:21:07 +0900 Message-ID: From: JINMEI Tatuya / =?ISO-2022-JP?B?GyRCP0BMQEMjOkgbKEI=?= To: "Sebastien Petit" In-Reply-To: <003001c41baf$5316dad0$6400a8c0@a91821794s3ti7g> <200403211226.13690.spe@selectbourse.net> References: <003b01c41b0f$b1e4fc90$bc0a270a@bum.sub.fr.hsbc> <003001c41baf$5316dad0$6400a8c0@a91821794s3ti7g> User-Agent: Wanderlust/2.10.1 (Watching The Wheels) Emacs/21.3 Mule/5.0 (SAKAKI) Organization: Research & Development Center, Toshiba Corp., Kawasaki, Japan. MIME-Version: 1.0 (generated by SEMI 1.14.5 - "Awara-Onsen") Content-Type: multipart/mixed; boundary="Multipart_Wed_Apr__7_00:21:07_2004-1" X-Mailman-Approved-At: Wed, 07 Apr 2004 05:02:55 -0700 cc: freebsd-net@freebsd.org cc: freebsd-hackers@freebsd.org Subject: Re: SOCK_RAW sockets and IPPROTO_AH X-BeenThere: freebsd-hackers@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Technical Discussions relating to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 06 Apr 2004 15:21:11 -0000 --Multipart_Wed_Apr__7_00:21:07_2004-1 Content-Type: text/plain; charset=US-ASCII >>>>> On Tue, 6 Apr 2004 10:15:29 +0200, >>>>> "Sebastien Petit" said: > Unfortunatly, I can't use bpf/pcap solution because I must do some > setsockopts (like IP_MULTICAST_IF, IP_MULTICAST_TTL, IP_MULTICAST_ADD_MEMBER > etc.) and this can't be done on bpf/pcap. > When I'm using IPPROTO_VRRP (ip proto 112), All work fine (and other ip > proto type I think). What is the reason that SOCK_RAW don't work with > IPPROTO_AH (ip proto 51). > For me, it's an IP packet in two cases. Let me check, why do you have to include AH by the application in the first place? Is that related to the question you made the other day (attached below)? JINMEI, Tatuya Communication Platform Lab. Corporate R&D Center, Toshiba Corp. jinmei@isl.rdc.toshiba.co.jp --Multipart_Wed_Apr__7_00:21:07_2004-1 Content-Type: message/rfc822 Return-Path: X-Mail-Format-Warning: Bad RFC2822 header formatting in >From jinmei Sun Mar 21 20:27:00 2004 Return-Path: X-Original-To: jinmei@shuttle.wide.toshiba.co.jp Delivered-To: jinmei@shuttle.wide.toshiba.co.jp Received: from shuttle.wide.toshiba.co.jp [202.249.10.124] by localhost with POP3 (fetchmail-6.2.4) for jinmei@localhost (single-drop); Sun, 21 Mar 2004 20:45:52 +0900 (JST) Received: from tsbgw.wide.toshiba.co.jp (tsbgw.wide.toshiba.co.jp [3ffe:501:100f:0:220:edff:fe2b:92c]) by shuttle.wide.toshiba.co.jp (Postfix) with ESMTP id 9D1EB15210 for ; Sun, 21 Mar 2004 20:27:00 +0900 (JST) Received: from maltese.wide.toshiba.co.jp (maltese.wide.toshiba.co.jp [202.249.10.99]) by tsbgw.wide.toshiba.co.jp (Postfix) with ESMTP id 7DC11330FB for ; Sun, 21 Mar 2004 20:27:00 +0900 (JST) Received: from isl.rdc.toshiba.co.jp (spiffy.isl.rdc.toshiba.co.jp [133.196.10.10]) by maltese.wide.toshiba.co.jp (8.9.1/8.9.1) with ESMTP id UAA24453 for ; Sun, 21 Mar 2004 20:27:00 +0900 (JST) Received: from mx4.toshiba.co.jp (mx4.toshiba.co.jp [133.199.160.112]) i2LBQx100075 for ; Sun, 21 Mar 2004 20:26:59 +0900 (JST) Received: from tsb-sgw2.toshiba.co.jp by toshiba.co.jp id UAA03644; Sun, 21 Mar 2004 20:26:59 +0900 (JST) Received: from inet-tsb5.toshiba.co.jp by tsb-sgw2.toshiba.co.jp with ESMTP id i2LBQwQD012005 for ; Sun, 21 Mar 2004 20:26:58 +0900 (JST) Received: from mx2.freebsd.org (mx2.freebsd.org [216.136.204.119]) by inet-tsb5.toshiba.co.jp with ESMTP id i2LBQv4u013439 for ; Sun, 21 Mar 2004 20:26:57 +0900 (JST) Received: from hub.freebsd.org (hub.freebsd.org [216.136.204.18]) by mx2.freebsd.org (Postfix) with ESMTP id 4E2FF569A6; Sun, 21 Mar 2004 03:26:38 -0800 (PST) (envelope-from owner-freebsd-net@freebsd.org) Received: from hub.freebsd.org (localhost [127.0.0.1]) by hub.freebsd.org (Postfix) with ESMTP id E935816A4DC; Sun, 21 Mar 2004 03:26:36 -0800 (PST) Delivered-To: freebsd-net@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id AB31816A4CE for ; Sun, 21 Mar 2004 03:26:22 -0800 (PST) Received: from smtp.noos.fr (nan-smtp-17.noos.net [212.198.2.117]) by mx1.FreeBSD.org (Postfix) with ESMTP id A3C5343D2D for ; Sun, 21 Mar 2004 03:26:21 -0800 (PST) (envelope-from spe@selectbourse.net) Received: (qmail 19099 invoked by uid 0); 21 Mar 2004 11:26:20 -0000 Received: from unknown (HELO 192.168.0.3) ([81.64.25.123]) (envelope-sender ) by 212.198.2.117 (qmail-ldap-1.03) with SMTP for ; 21 Mar 2004 11:26:20 -0000 From: Sebastien Petit Organization: BSDShell To: freebsd-net@freebsd.org Date: Sun, 21 Mar 2004 12:26:13 +0100 User-Agent: KMail/1.5.2 MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200403211226.13690.spe@selectbourse.net> Subject: IPSec and setsockopt MULTICAST_IF interaction X-BeenThere: freebsd-net@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Networking and TCP/IP with FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: owner-freebsd-net@freebsd.org Errors-To: owner-freebsd-net@freebsd.org X-UIDL: %!$"!=@7!!G&~"!h89!! X-Spam-Level: * X-Spam-Checker-Version: SpamAssassin 2.61 (1.212.2.1-2003-12-09-exp) on ocean.jinmei.org X-Spam-Status: No, hits=1.5 required=5.0 tests=RCVD_NUMERIC_HELO autolearn=no version=2.61 Hi Team, I want to use IPsec engine with AH Security Association and SPD on multicast destination adress. When I comment the setsockopt MULTICAST_IF option, all work fine and destination packets to the multicast adress have AH added before IP Header. But when I use the setsockopt MULTICAST_IF, no packets are sended from the interface (packet seems to be destroyed silently by kernel). Is there an issue about using MUTLICAST_IF option and IPsec ? Any help will be greatly appreciated. Regards, spe. -- spe@selectbourse.net _______________________________________________ freebsd-net@freebsd.org mailing list http://lists.freebsd.org/mailman/listinfo/freebsd-net To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org" --Multipart_Wed_Apr__7_00:21:07_2004-1--