Re: IPSec troubles

From: Bjoern A. Zeeb (bzeeb-lists_at_lists.zabbadoz.net)
Date: 03/30/04

  • Next message: Cyrill Rüttimann: "Re: IPSec troubles"
    Date: Tue, 30 Mar 2004 11:22:08 +0000 (UTC)
    To: "Crist J. Clark" <cjc@freebsd.org>
    
    

    On Mon, 29 Mar 2004, Crist J. Clark wrote:

    > > I have troubles setting up an IPSec Host-to-Host connection between
    > > FreeBSD 5.2.1 and MacOS X 10.3.3:
    >
    > Last I knew, 5.2.1 still had broken IPsec. Specifically, the system
    > tries to apply the IPsec policy to the IKE traffic giving us a chicken
    > and egg problem.

    you can "exclude" IKE traffic in the SPD manually. I am still unsure
    if this IS a bug. Would need to go through RFCs in detail.

    Just skipped through 2401 and what I have found is:

       In host systems, applications MAY be allowed to select what security
       processing is to be applied to the traffic they generate and consume.

    and

       The SPD is used to control the flow of ALL traffic through an IPsec
       system, including security and key management traffic (e.g., ISAKMP)
       from/to entities behind a security gateway. This means that ISAKMP
       traffic must be explicitly accounted for in the SPD, else it will be
       discarded.

    So if I get the problem right racoon is unable to tell the kernel
    that it's traffic should 'bypass' IPSec processing ?

    If this is the remaining problem apart from the yet known (where KAME
    people cannot find the time to review at the moment) I may look into
    this; have setup my wireless connection on a 5.2.1 notebook (being
    updated to HEAD soon) to use IPSec lately so I have a 'testbed' now.

    -- 
    Greetings
    Bjoern A. Zeeb				bzeeb at Zabbadoz dot NeT
    56 69 73 69 74				http://www.zabbadoz.net/
    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"
    

  • Next message: Cyrill Rüttimann: "Re: IPSec troubles"

    Relevant Pages

    • IPSEC Tunnel Down
      ... ISAKMP: set new node 0 to QM_IDLE ... crypto_engine: Encrypt IKE packet ... ISAKMP::Checking IPSec proposal 1 ...
      (comp.dcom.sys.cisco)
    • PIX525 - Setup ipsec tunnel to two Nortel FW sharing the same subnet
      ... I'm trying to setup ipsec tunnels to two Nortel boxes ... sharing the same subnet from a CISCO PIX-525E running under 6.3. ... Debug crypto isakmp ...
      (comp.dcom.sys.cisco)
    • Re: [fw-wiz] Pix to Vigor VPN
      ... isakmp is finishing OK, but the problem is from the IPSec engine. ... > fixup protocol http 80 ... > logging timestamp ...
      (Firewall-Wizards)
    • Re: Ike phase 1 rekey & timeout
      ... there & Phase1 rekey fails ... that give Isakmp SA duration more than IPsec SA duration. ... features are not related & since I am not getting any keepalives Phase ...
      (comp.dcom.sys.cisco)
    • Re: IP SEC filtering issue
      ... > the IPSEC processing gets done it the kernel, ... we can just filter that out. ... >> If any of you know of a way to get ipsec to filter on syn packets ...
      (FreeBSD-Security)