netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* IPsec tunnel mode bug - malformed, misaddressed packets
@ 2004-10-17 11:52 Christopher K. Johnson
  2004-10-18  1:08 ` Herbert Xu
  0 siblings, 1 reply; 4+ messages in thread
From: Christopher K. Johnson @ 2004-10-17 11:52 UTC (permalink / raw)
  To: netdev

There is an ipsec bug in FC2 kernel 2.6.8-1.521 for ipsec tunnel mode.
I have proven with a packet trace that some packets are
misaddressed.  Specifically it constructs a packet of the form:
 IP header1 | AH header | IP header2 | ESP
The IP header1 has an incorrect destination address of the host in the
remote tunneled subnet instead of the remote vpn partner, whereas IP
header2 has the correct destination address of the remote vpn partner.

For an host in local ipsec subnet contacting a web server in remote
ipsec subnet the initial syn and response of syn,ack are tunnelled
successfuly, but the encrypted ack goes out malformed as indicated above,
thus is never delivered.

Packet trace and setkey config are attached to bugzilla entry at 
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=132832

Your help in resolving this bug so ipsec is usable would be appreciated greatly.

Chris

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2004-10-18 23:49 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-10-17 11:52 IPsec tunnel mode bug - malformed, misaddressed packets Christopher K. Johnson
2004-10-18  1:08 ` Herbert Xu
2004-10-18 23:17   ` Christopher K. Johnson
2004-10-18 23:49     ` Herbert Xu

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).