All of lore.kernel.org
 help / color / mirror / Atom feed
* 2.6.16-rc1-mm3 XFRM+NAT issue
@ 2006-01-29 19:41 Christophe Saout
  2006-01-29 19:57 ` Patrick McHardy
  0 siblings, 1 reply; 14+ messages in thread
From: Christophe Saout @ 2006-01-29 19:41 UTC (permalink / raw)
  To: netfilter-devel; +Cc: Patrick McHardy, Herbert Xu

[-- Attachment #1: Type: text/plain, Size: 1904 bytes --]

Hi,

I'm very glad that you found some time to get these patches into the
mainline kernel. Unfortunately I think I'm running into a case where
it's not working (it's working with 2.6.12 + the old unofficial IPSEC
+NAT patches).

          .--- gateway host ---.            .-- pub. host -.
priv net -|NAT + IPSEC endpoint|- internet -|IPSEC endpoint|
          '--------------------'            '--------------'

ping ----->---*NAT*---*XFRM*********>*********XFRM*--------.
                                                           v
                   ???.....*********<*********XFRM*- pong -'

Without IPSEC turned on I can reach the host on the far right from any
host in the private network on the left without problem. The private
address is source-NATted (masqueraeded) at the gateway.

When turning on the IPSEC connection between the gateway and the
internet host, the host in the private network can't reach the internet
host (on the right) anymore. It's still reachable from the gateway
itself though.

When pinging from the host behind the gateway the packet passes through
the gateway, gets to the internet host, which responds to the ping and
sends an encrypted packet back through the IPSEC connection which then
arrives at the gatway. But then the gateway simply ignores the packet
instead of decapsulating and DNATting it back to the host in the private
network. At least that's what I can gather from tcpdump. If I run
tcpdump on ppp0 on the gateway I can see encrypted packets go out to the
host on the right and encrypted packets coming back and that's it.

I couldn't exactly keep track with all the changes since 2.6.12 and I
was hoping that this kernel would just work and fulfill my needs... and
I still don't really "get" the networking stack I have no clue where to
start looking what could go wrong.

So, do you perhaps have any ideas?


[-- Attachment #2: Dies ist ein digital signierter Nachrichtenteil --]
[-- Type: application/pgp-signature, Size: 189 bytes --]

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2006-02-03 10:24 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-01-29 19:41 2.6.16-rc1-mm3 XFRM+NAT issue Christophe Saout
2006-01-29 19:57 ` Patrick McHardy
2006-01-29 20:59   ` Christophe Saout
2006-01-29 22:14     ` Patrick McHardy
2006-01-29 22:30       ` Christophe Saout
2006-01-29 22:43         ` Patrick McHardy
2006-01-29 23:11           ` Christophe Saout
2006-01-29 22:59         ` Patrick McHardy
2006-01-29 23:24           ` Christophe Saout
2006-01-29 23:26             ` Patrick McHardy
2006-01-29 23:29               ` Patrick McHardy
2006-01-29 23:30               ` Christophe Saout
2006-02-03  1:16           ` David S. Miller
2006-02-03 10:24             ` Patrick McHardy

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.