All of lore.kernel.org
 help / color / mirror / Atom feed
From: rsnel@cube.dyndns.org
To: netfilter@lists.netfilter.org
Subject: Re: 26sec+forwarding, bug or PEBKAC?
Date: Wed, 6 Apr 2005 23:25:13 +0200	[thread overview]
Message-ID: <20050406212513.GA19637@cube.dyndns.org> (raw)
In-Reply-To: <9C1918067C3BC14C9C351C206D8A8437372FF2@rennsmail03.eu.thmulti.com>


Hi,

On Wed, Apr 06, 2005 at 02:36:10PM +0200, Allain Yoann wrote:
> > On Tue, 31 Mar 2005 22:16:40, rsnel at cube.dyndns.org wrote
> > >
> > >packets from ipsec tunnel seem to get lost before they enter the the
> > >FORWARD chain with kernel 2.6.11. There is no problem with 2.6.8-2-k6
> > >(Debian kernel with 26sec) and there is no problem with ipsec turned
> > >off.
> > > [...]
> > >So, is it a bug, feature, or just misconfiguration? Can you reproduce?
> > >I would appreciate any insight on this problem.
> 
> I solved the problem:
> Since the kernel 2.6.10, we must set a "fwd" policy in the same way we
> did for the "in" policy on each host-end of the tunnel.
> 
> I just found one reference on the web:
> http://www.ipsec-howto.org/x277.html (one line in the middle)
> 
> I hope others newbies like me won't lose too much time on it...

Many thanks Allain for your solution. (I didn't try it out yet, but I
expect it to work) And so problem turned out to be misconfiguration of a
new feature...

Greetings,

Rik.



  reply	other threads:[~2005-04-06 21:25 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-04-06 12:36 26sec+forwarding, bug or PEBKAC? Allain Yoann
2005-04-06 21:25 ` rsnel [this message]
  -- strict thread matches above, loose matches on Subject: below --
2005-04-06  8:54 Allain Yoann
2005-03-31 20:16 rsnel

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20050406212513.GA19637@cube.dyndns.org \
    --to=rsnel@cube.dyndns.org \
    --cc=netfilter@lists.netfilter.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.