(racoon 713) Interoparability with FW-1 broken, patch included

Steffen Neumann <[email protected]> Wed, 08 Sep 2004 11:51:02 +0200
Newsgroups gmane.network.ipv6.kame.racoon
Organization Institute for Plant genomics and Culture Plants
Message-ID <1094637062.4115.33.camel@localhost>
Hi,

disclaimer: I am not an ipsec guru,
and just want to report that a connection
to our FW-1 worked back in Juli, broke after 
an FW-1 upgrade, and works again due to my 
hack in the racoon code, which is not intended
to be used upstream, but to indicate where the problem was/is.

Back on-topic:
System is a Debian Laptop, Kernel 2.6.8, with racoon 0.3.3. Remote is a
CheckPoint FW-1, R55. The FW-1 seems to be sending a CRL within the
ISAKMP handshake, which confused racoon. I hacked oakley.c to ignore
that error, and the connection opens again.

I hope this will help to diagnose the problem
and create a proper fix in some future version,

yours,
Steffen

P.S.: Please Cc: me directly, since I will
unsubscribe from the list right away.

------------------------------

--- oakley.c    2004-08-24 12:03:16.000000000 +0200
+++ oakley.c~   2004-06-15 15:36:45.000000000 +0200
@@ -1940,7 +1940,7 @@
        default:
                plog(LLV_ERROR, LOCATION, NULL,
                        "Invalid CR type %d\n", type);
-               return 0; /* STN: UGLY HACK !!!!*/
+               return -1;
        }

        *c = save_certbuf(gen);
------------------------------

INFO: @(#)ipsec-tools 0.3.3 (http://ipsec-tools.sourceforge.net)
INFO: @(#)This product linked OpenSSL 0.9.7d 17 Mar 2004
(http://www.openssl.org/)
DEBUG: compression algorithm can not be checked because sadb message
doesn't
support it.
DEBUG: my interface: 127.0.0.1 (lo)
DEBUG: my interface: AAA.BBB.9.195 (eth0)
DEBUG: configuring default isakmp port.
DEBUG: 2 addrs are configured successfully
INFO: AAA.BBB.9.195[500] used as isakmp port (fd=7)
INFO: 127.0.0.1[500] used as isakmp port (fd=8)

DEBUG: get pfkey X_SPDDUMP message
DEBUG: get pfkey X_SPDDUMP message
DEBUG: sub:0xbffffb00: XXX.YYY.ZZZ.129/27[0] AAA.BBB.9.195/32[0]
proto=any dir=in
DEBUG: db :0x80a5f10: XXX.YYY.ZZZ.8/29[0] AAA.BBB.9.195/32[0] proto=any
dir=in
DEBUG: get pfkey X_SPDDUMP message
DEBUG: sub:0xbffffb00: AAA.BBB.9.195/32[0] XXX.YYY.ZZZ.8/29[0] proto=any
dir=out
DEBUG: db :0x80a5f10: XXX.YYY.ZZZ.8/29[0] AAA.BBB.9.195/32[0] proto=any
dir=in
DEBUG: sub:0xbffffb00: AAA.BBB.9.195/32[0] XXX.YYY.ZZZ.8/29[0] proto=any
dir=out
DEBUG: db :0x80a6148: XXX.YYY.ZZZ.129/27[0] AAA.BBB.9.195/32[0]
proto=any dir=in
DEBUG: get pfkey X_SPDDUMP message
DEBUG: sub:0xbffffb00: AAA.BBB.9.195/32[0] XXX.YYY.ZZZ.129/27[0]
proto=any dir=out
DEBUG: db :0x80a5f10: XXX.YYY.ZZZ.8/29[0] AAA.BBB.9.195/32[0] proto=any
dir=in
DEBUG: sub:0xbffffb00: AAA.BBB.9.195/32[0] XXX.YYY.ZZZ.129/27[0]
proto=any dir=out
DEBUG: db :0x80a6148: XXX.YYY.ZZZ.129/27[0] AAA.BBB.9.195/32[0]
proto=any dir=in
DEBUG: sub:0xbffffb00: AAA.BBB.9.195/32[0] XXX.YYY.ZZZ.129/27[0]
proto=any dir=out
DEBUG: db :0x80a6380: AAA.BBB.9.195/32[0] XXX.YYY.ZZZ.8/29[0] proto=any
dir=out
DEBUG: get pfkey ACQUIRE message
DEBUG: suitable outbound SP found: AAA.BBB.9.195/32[0]
XXX.YYY.ZZZ.8/29[0]
proto=any dir=out.
DEBUG: sub:0xbffffae0: XXX.YYY.ZZZ.8/29[0] AAA.BBB.9.195/32[0] proto=any
dir=in
DEBUG: db :0x80a5f10: XXX.YYY.ZZZ.8/29[0] AAA.BBB.9.195/32[0] proto=any
dir=in
DEBUG: suitable inbound SP found: XXX.YYY.ZZZ.8/29[0]
AAA.BBB.9.195/32[0]
proto=any dir=in.
DEBUG: new acquire AAA.BBB.9.195/32[0] XXX.YYY.ZZZ.8/29[0] proto=any
dir=out
DEBUG: anonymous sainfo selected.
DEBUG:  (proto_id=ESP spisize=4 spi=00000000 spi_p=00000000
encmode=Tunnel
reqid=0:0)
DEBUG:   (trns_id=3DES encklen=0 authtype=hmac-sha)
DEBUG: anonymous configuration selected for XXX.YYY.ZZZ.34.
INFO: IPsec-SA request for XXX.YYY.ZZZ.34 queued due to no phase1 found.

DEBUG: ===
INFO: initiate new phase 1 negotiation:
AAA.BBB.9.195[500]<=>XXX.YYY.ZZZ.34[500]
INFO: begin Identity Protection mode.
DEBUG: new cookie: a7827f66b1c313e7
DEBUG: add payload of len 48, next type 0
DEBUG: 80 bytes from AAA.BBB.9.195[500] to XXX.YYY.ZZZ.34[500]
DEBUG: sockname AAA.BBB.9.195[500]
DEBUG: send packet from AAA.BBB.9.195[500]
DEBUG: send packet to XXX.YYY.ZZZ.34[500]
DEBUG: src4 AAA.BBB.9.195[500]
DEBUG: dst4 XXX.YYY.ZZZ.34[500]
DEBUG: 1 times of 80 bytes message will be sent to AAA.BBB.9.195[500]
DEBUG:  a7827f66 b1c313e7 00000000 00000000 ...
DEBUG: resend phase1 packet a7827f66b1c313e7:0000000000000000

DEBUG: ===
DEBUG: 80 bytes message received from XXX.YYY.ZZZ.34[500] to
AAA.BBB.9.195[500]
DEBUG:  a7827f66 b1c313e7 34fe8d1b 3f347d37 01100200 00000000 00000050
00000034
00000001 00000001 00000028 01010001 00000020 01010000 800b0001 800c7080
80010005 80030003 80020001 80040002
DEBUG: begin.
DEBUG: seen nptype=1(sa)
DEBUG: succeed.
DEBUG: total SA len=48
DEBUG:  00000001 00000001 00000028 01010001 00000020 01010000 800b0001
800c7080
80010005 80030003 80020001 80040002
DEBUG: begin.
DEBUG: seen nptype=2(prop)
DEBUG: succeed.
DEBUG: proposal #1 len=40
DEBUG: begin.
DEBUG: seen nptype=3(trns)
DEBUG: succeed.
DEBUG: transform #1 len=32
DEBUG: type=Life Type, flag=0x8000, lorv=seconds
DEBUG: type=Life Duration, flag=0x8000, lorv=28800
DEBUG: type=Encryption Algorithm, flag=0x8000, lorv=3DES-CBC
DEBUG: encription(3des)
DEBUG: type=Authentication Method, flag=0x8000, lorv=RSA signatures
DEBUG: type=Hash Algorithm, flag=0x8000, lorv=MD5
DEBUG: hash(md5)
DEBUG: type=Group Description, flag=0x8000, lorv=1024-bit MODP group
DEBUG: hmac(modp1024)
DEBUG: pair 1:
DEBUG:  0x80a6d20: next=(nil) tnext=(nil)

DEBUG: proposal #1: 1 transform
DEBUG: prop#=1, prot-id=ISAKMP, spi-size=0, #trns=1
DEBUG: trns#=1, trns-id=IKE
DEBUG: type=Life Type, flag=0x8000, lorv=seconds
DEBUG: type=Life Duration, flag=0x8000, lorv=28800
DEBUG: type=Encryption Algorithm, flag=0x8000, lorv=3DES-CBC
DEBUG: type=Authentication Method, flag=0x8000, lorv=RSA signatures
DEBUG: type=Hash Algorithm, flag=0x8000, lorv=MD5
DEBUG: type=Group Description, flag=0x8000, lorv=1024-bit MODP group
DEBUG: Compared: DB:Peer
DEBUG: (lifetime = 28800:28800)
DEBUG: (lifebyte = 0:0)
DEBUG: enctype = 3DES-CBC:3DES-CBC
DEBUG: (encklen = 0:0)
DEBUG: hashtype = MD5:MD5
DEBUG: authmethod = RSA signatures:RSA signatures
DEBUG: dh_group = 1024-bit MODP group:1024-bit MODP group
DEBUG: an acceptable proposal found.
DEBUG: hmac(modp1024)

DEBUG: ===
DEBUG: compute DH's private.
DEBUG:  67996a24 3bfb1d0c ...
DEBUG: compute DH's public.
DEBUG:  d23fb26c a9772291 ...
DEBUG: add payload of len 128, next type 10
DEBUG: add payload of len 16, next type 0
DEBUG: 180 bytes from AAA.BBB.9.195[500] to XXX.YYY.ZZZ.34[500]
DEBUG: sockname AAA.BBB.9.195[500]
DEBUG: send packet from AAA.BBB.9.195[500]
DEBUG: send packet to XXX.YYY.ZZZ.34[500]
DEBUG: src4 AAA.BBB.9.195[500]
DEBUG: dst4 XXX.YYY.ZZZ.34[500]
DEBUG: 1 times of 180 bytes message will be sent to AAA.BBB.9.195[500]
DEBUG:  a7827f66 b1c313e7 ...
DEBUG: resend phase1 packet a7827f66b1c313e7:34fe8d1b3f347d37
DEBUG: ===
DEBUG: 306 bytes message received from XXX.YYY.ZZZ.34[500] to
AAA.BBB.9.195[500]
DEBUG:  a7827f66 b1c313e7 34fe8d1b ...
DEBUG: begin.
DEBUG: seen nptype=4(ke)
DEBUG: seen nptype=10(nonce)
DEBUG: seen nptype=7(cr)
DEBUG: succeed.
DEBUG: CR saved:
DEBUG:  301a3118 30160603 55040a13 0f667731 2d657874 2e2e6d39 34786435
ERROR: Invalid CR type 7

DEBUG: ===
DEBUG: 306 bytes message received from XXX.YYY.ZZZ.34[500] to
AAA.BBB.9.195[500]
DEBUG:  a7827f66 b1c313e7 34fe8d1b ...
DEBUG: begin.
DEBUG: seen nptype=4(ke)
DEBUG: seen nptype=10(nonce)
DEBUG: seen nptype=7(cr)
DEBUG: succeed.
DEBUG: CR saved:
DEBUG:  301a3118 30160603 55040a13 0f667731 2d657874 2e2e6d39 34786435
ERROR: Invalid CR type 7
DEBUG: ===
DEBUG: 306 bytes message received from XXX.YYY.ZZZ.34[500] to
AAA.BBB.9.195[500]
DEBUG:  a7827f66 b1c313e7 34fe8d1b ...
DEBUG: begin.
DEBUG: seen nptype=4(ke)
DEBUG: seen nptype=10(nonce)
DEBUG: seen nptype=7(cr)
DEBUG: succeed.
DEBUG: CR saved:
DEBUG:  301a3118 30160603 55040a13 0f667731 2d657874 2e2e6d39 34786435
ERROR: Invalid CR type 7

[...]



-- 
Dr. Steffen Neumann		Phone:	+49(0)39482 5 736
http://pdw.bic-gh.de/		Fax:	+49(0)39482 5 xxx		

IPK Gatersleben - Correnstr. 3 - 06466 Gatersleben
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)

iD8DBQBBPtYGIjiqkZALm0oRAn3QAJ4zb+/yigfLQWqahl/WDbJ3hbvzGwCeMrHd
r8iOapdLPqHmpWGe3PPOi78=
=FMm8
-----END PGP SIGNATURE-----