5.3-RELEASE w/ IPSEC & RACOON

From: Matthew T. Lager (freebsd_at_trinetworks.com)
Date: 11/07/04

  • Next message: FreeBSD bugmaster: "Current problem reports assigned to you"
    Date: Sat, 6 Nov 2004 17:54:55 -0800 (PST)
    To: freebsd-net@freebsd.org
    
    

    Good Morning!

    I have a simple tunnel established between two FreeBSD machines. The
    tunnel is encrypted using IPSEC and Racoon. Prior to 5.3-*, I have never
    experienced any issues with it.

    Using the same configuration in 5.3-*, the tunnel is still established and
    simple traffic can be sent across the tunnel. When a sudden burst of
    packets is sent through the tunnel, that particular connection completly
    and permanantly freezes. An example of this is a simple SSH session to
    another FreeBSD machine where a dmesg is issued. About 5 lines into the
    dmesg, the connection freezes up.

    I have read a lot about the MPSAFE/GIANT situation in 5.3-*, and noticed
    that my kernel warned me that MPSAFE was forced to be disabled due to
    IPSEC's requirement to be in a GIANT-LOCKED environment. I havn't yet
    determined that this particular issue is what is causing my problems.

    When racoon is disabled and IPSEC is removed from the kernel, I do not
    experience this issue.

    Does anyone have any ideas or information? Thanks in advance!

    Matt Lager

    _______________________________________________
    freebsd-net@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-net
    To unsubscribe, send any mail to "freebsd-net-unsubscribe@freebsd.org"


  • Next message: FreeBSD bugmaster: "Current problem reports assigned to you"

    Relevant Pages

    • Re: Wifi ipsec freebsd
      ... I too have set up a ipsec secured wireless network and this article ... Tunnel vs. transport mode was something I never fully understood. ... connection over wifi between a FreeBSD gateway and a Windows laptop. ...
      (freebsd-questions)
    • Re: freebsd-security Digest, Vol 201, Issue 2
      ... freebsd vpn server behind nat dsl router ... which allows IPSec tunnels to be established if there is some NAT ... I have created an esp tunnel between my two sites, ...
      (FreeBSD-Security)
    • RE: IPSec vs. IPSec/L2TP
      ... The reason people use L2TP is due the need to provide login mechanism ... logging and the rest of the session would be using IPSec. ... > L2TP/IPSec tunnelling instead of a good old IPSec tunnel. ... Earn your MS in Information Security ONLINE ...
      (Security-Basics)
    • Re: esp tunnel without gif(4) [Was Re: vpn1/fw1 NG to ipsec/racoontroubles, help please ...]
      ... The IPSEC peer gateway is also defined for each spdadd so ... peer gateways are actually defined by the private tunnel interface end ... I have attached my config script as an example. ...
      (FreeBSD-Security)
    • Re: IPSEC config
      ... >> I'm trying to setup a IPSec tunnel and am having trouble. ... >> for a transport between the two machines it works fine, ... >> I'm following the IPsec mini-HOWTO from January 2001 daemonnews. ...
      (FreeBSD-Security)