Re: gre tunnel & ipsec transport mode

From: Helge Oldach (helge.oldach_at_atosorigin.com)
Date: 12/17/03

  • Next message: Markus Oestreicher: "Polling CPU usage"
    To: e-masson@kisoft-services.com (Eric Masson)
    Date: Wed, 17 Dec 2003 09:32:31 +0100 (MET)
    
    

    Eric Masson:
    >I'm experimenting dynamic routing protocols in a vpn setup. Ipsec tunnel
    >mode is not applicable here as selectors do not appear in system routing
    >table.

    I think the problem is that you need multicasts to exchange routing
    updates through the tunnel. If I am not mistaken that is supported with
    gif interfaces as well. Maybe you could do away with gif?

    >On destination box, tcpdump shows incoming ipsec gre transformed
    >packets, but these packets don't make their way to internal interface,
    >and are silently dropped (no log anywhere)

    This is odd. Do you have a chance to test this against another IPSec
    box, e.g. a Cisco router configured with a GRE Tunnel interface?

    Helge
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: Markus Oestreicher: "Polling CPU usage"

    Relevant Pages

    • Re: Routing IPSEC packets?
      ... over the tunnels, I'd just use IPsec tunnel mode at ... IPsec is not integrated in anyway with IP routing. ...
      (freebsd-net)
    • Debugging an IPSec tunnel on PIX515
      ... I need to set up an IPSec tunnel between a PIX 515E and a NetScreen unit ... access-list external permit icmp any any echo-reply ... crypto map external-ipsec 10 match address Tunnel ...
      (comp.dcom.sys.cisco)
    • ospf / gif / packets not pushed into gif tunnel
      ... I'm trying to get dynamic routing working between two private networks. ... A gif tunnel is created between the two networks. ... The central server ...
      (freebsd-net)
    • Re: source based routing help needed
      ... any traffic that comes in on the eth0 interface needs to go back out on ... I have this sort of working using standard routing where the 'default' ... route goes over my tunnel so any web traffic that comes in, ... route via eth0. ...
      (comp.os.linux.networking)
    • Re: Restricting IPSEC traffic
      ... you can terminate the IPSEC tunnel on an actual tunnel interface and ... than the encapsulated packet. ... lists in sync and also assumes that the packets are routable independent ... of the IPSEC tunnel. ...
      (comp.dcom.sys.cisco)