netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* packets displayed twice on ipsec interface ...
@ 2004-12-26 19:01 Christiaan den Besten
  0 siblings, 0 replies; only message in thread
From: Christiaan den Besten @ 2004-12-26 19:01 UTC (permalink / raw)
  To: netdev

Hi all !

Not really sure this is a kernel, or a netfilter issue, but posting to 
the lkml resulted in no answers so far ;(

After trying to determine the 'overhead' of my ipsec traffic, I hit a 
rather annoying 'feature'.

(Using racoon ipsec with default debian-kernels 2.6.x kernels, but issue 
was with 2.4 as well if i remember correctly.)

Traffic on the outgoing interface (eth0) shows both the encapsulated as 
well as the non-encapsulated packets.

--- (tcpdump -i eth0 -n ) ---
15:24:20.003088 IP 172.20.40.45.45707 > 10.136.100.1.48193: . 
297216:298592(1376) ack 1 win 5792 <nop,nop,timestamp 920412777 2654747912>
15:24:20.005095 IP 130.161.82.9 > 84.35.71.36: 
ESP(spi=0x080d4f70,seq=0x1de7c)
15:24:20.005095 IP 172.20.40.45.45707 > 10.136.100.1.48193: . 
298592:299968(1376) ack 1 win 5792 <nop,nop,timestamp 920412777 2654747912>
15:24:20.005223 IP 84.35.71.36 > 130.161.82.9: 
ESP(spi=0x0451e539,seq=0xee8e)
---

Using default tools a la 'iptraf' counts them both, so it would look 
like my adsl-line is doing 11Mbit :) (which is rather nice since the 
telco has limited it to 6Mbit ...)

Is there any way to prevent the kernel from showing the data inside the 
tunnel ? (172.20.40.45 <> 10.136.100.1 is the tunneled traffic).

bye,
Chris

( Not a member of the list, so a cc would be very nice )

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2004-12-26 19:01 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-12-26 19:01 packets displayed twice on ipsec interface Christiaan den Besten

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).