Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 02 Apr 2003 08:20:49 -0800
From:      Lars Eggert <larse@ISI.EDU>
To:        Eric Masson <e-masson@kisoft-services.com>
Cc:        Mailing List FreeBSD Network <freebsd-net@freebsd.org>
Subject:   Re: options FAST_IPSEC & tunnels
Message-ID:  <3E8B0DE1.1030500@isi.edu>
In-Reply-To: <86fzp0riwl.fsf@notbsdems.interne.kisoft-services.com>
References:  <86pto6mbxj.fsf@notbsdems.interne.kisoft-services.com> <05b901c2f881$67e907f0$52557f42@errno.com> <3E8A1122.5040304@isi.edu> <86fzp0riwl.fsf@notbsdems.interne.kisoft-services.com>

next in thread | previous in thread | raw e-mail | index | archive | help

[-- Attachment #1 --]
Eric,

On 4/2/2003 7:58 AM, Eric Masson wrote:
>>>>>>"Lars" == Lars Eggert <larse@ISI.EDU> writes:
> 
>  Lars> Alternatively (and already working), you can replace IPsec tunnel
>  Lars> mode with IPIP (gif) tunnels and transport mode, and then use the
>  Lars> gif device in your firewall rules.
> 
> If transport mode can be used to connect to a pix, it's a solution to
> consider, but atm, I've found no reference to such a setup on the pix.

what's a pix? But chances are, you will need to control both endpoints 
for my suggestion to work.

> I've tried gif tunnels with ipsec tunnel mode and didn't get
> reproduceable results, this setup worked once with the following gif
> setup :
[snip]
> Next time, after a reboot (kernel switch) no packets were flowing thru
> the gif tunnel.

Yes, combining tunnel mode and IPIP tunnels is not a good idea. 
Basically, that approach creates two parallel virtual topologies, one 
out of IPIP tunnels, and one out of IPsec tunnel mode SAs. People often 
do this, because they want to route traffic into an IPsec tunnel, and 
the SA itself doesn't have a route entry, since they aren't devices. 
When using IPIP tunnels with tunnel mode, they abuse the route created 
by the gif device for routing, but packets will be hijacked by the 
tunnel mode SA, so they never actually enter gif processing (IPsec does 
the IPIP encapsulation internally.)

Using IPIP tunnels with transport mode is valid, since packets will 
actually flow through the gif device, and get IPsec'ed after they are 
IPIP encapsulated. (In multihop topologies, they'll then need to be IPIP 
encapsulated again - the virtual network needs both virtual link and 
network layers.)

Lars
-- 
Lars Eggert <larse@isi.edu>           USC Information Sciences Institute

[-- Attachment #2 --]
0	*H
010	+0	*H
	080fErtcvE.0
	*H
010	UZA10UWestern Cape10U	Cape Town10U
Thawte Consulting1(0&UCertification Services Division1$0"UThawte Personal Freemail CA1+0)	*H
	personal-freemail@thawte.com0
000830000000Z
040827235959Z010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.3000
	*H
032c	%E>nx'gڈD)c5*mp<ܮto034qmOe
KaU5u'rװ|CBPQ<9TIf-	kiN0L0)U"0 010UPrivateLabel1-2970U00U0
	*H
1KG]qSl]y=&b""I'{9$
*8PUl
LGlX1B	li+@]jy.%݊
Z<D&iHΥbb090%A0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
020824185339Z
030824185339Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu0"0
	*H
0
6Fxΰ7aED&0+Dj)ֽXCUcnleijmz~S0JjWV~	1^({IݛLjӖ
ao:bP}WLVܱ욗cDɖ_Kv.A(W49;Z8-uXE
6b
@_0%#d`Rto5 L0R`w@7
r	Hcc	U3%7N_oV0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
]Ȕ,fK<cjRZeLan@Z6,=
fK?yO#8+	Ni*LSfpQg<(aӒ$kTx_AL1>ގ|S090%A0
	*H
010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.300
020824185339Z
030824185339Z0T10
UEggert1
0U*Lars10ULars Eggert10	*H
	
larse@isi.edu0"0
	*H
0
6Fxΰ7aED&0+Dj)ֽXCUcnleijmz~S0JjWV~	1^({IݛLjӖ
ao:bP}WLVܱ욗cDɖ_Kv.A(W49;Z8-uXE
6b
@_0%#d`Rto5 L0R`w@7
r	Hcc	U3%7N_oV0T0*+e!000L2uMyffBNUbNJJcdZ2s0U0
larse@isi.edu0U00
	*H
]Ȕ,fK<cjRZeLan@Z6,=
fK?yO#8+	Ni*LSfpQg<(aӒ$kTx_AL1>ގ|S100010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0	+0	*H
	1	*H
0	*H
	1
030402162049Z0#	*H
	1R
9m,zK26<$0R	*H
	1E0C0
*H
0*H
0
*H
@0+0
*H
(0	+710010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0*H
	1010	UZA10UWestern Cape10U	Cape Town10
U
Thawte10UCertificate Services1(0&UPersonal Freemail RSA 2000.8.30%A0
	*H
sND# &_#!J1>}T`tk('es@?U0^p`cr0"e5.or~+zEawtKJ+ 13sXoiy/&Ml]1UNO#eꔳԕkx.9Gq"Y@sc$ 2Օȝ{UB_eFsqa#<xZN-u[s5'qV

Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3E8B0DE1.1030500>