public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* Kernel 2.6.10 with IPSEC problems?
@ 2004-12-26 14:53 Joerg Platte
  2004-12-26 15:39 ` Patrick McHardy
  0 siblings, 1 reply; 4+ messages in thread
From: Joerg Platte @ 2004-12-26 14:53 UTC (permalink / raw)
  To: linux-kernel

Hi!

After an upgrade from 2.6.9 to 2.6.10 my IPSEC tunnel does not work as usual. 
My computer and the VPN-gateway can negotiate and build a tunnel and packets 
can use the tunnel. But then packets which must be routed get lost somewhere 
inside the kernel. tcpdump shows them first encrypted in ESP packets and then 
the unencrypted payload on the same interface. But they do not leave the 
kernel on the destination interface. Only packets with my computer as 
destination are processed. I did not change my IPSEC configuration and the 
kernel was configured using "make oldconfig".

Is there a problem in the routing layer somewhere inside the kernel or an 
internal change which requires a configuration change on my side? How can I 
determine, where and why the packets inside the kernel are thrown away?

To verify the problem I build a 2.6.10 kernel on the VPN gateway. And this 
kernel seems to have the same problem. Previously encrypted packets are not 
routed to th destination.

Downgrading to 2.6.9 solved the problem in both cases...

Regards,
Jörg

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2004-12-26 18:43 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-12-26 14:53 Kernel 2.6.10 with IPSEC problems? Joerg Platte
2004-12-26 15:39 ` Patrick McHardy
2004-12-26 18:15   ` Joerg Platte
2004-12-26 18:42     ` Patrick McHardy

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox