(racoon 731) Re: Ipsec header encrypted?
[email protected] Sun, 12 Sep 2004 17:50:52 +0200
| Newsgroups | gmane.network.ipv6.kame.racoon |
|---|---|
| Message-ID | <[email protected]> |
Yes I do! Ok I understand what you mean, but unfortunately I have no other box to test it. So I hope you are right ;-) thanks! Selon Aidas Kasparas <[email protected]>: > I suspect, there is NO PROBLEM! You do tcpdump on zeus, don't you? > > If yes, then look what happens: > - esp-encapsulated packet comes via interface and is noticed by tcpdump; > - esp header is removed and resulting packet enters kernel code as if it > was just received from the same network interface hardware. tcpdump > notices it this time with full headers. > > Please, try to tcpdump from different box which could hear all zeus > external traffic, and I believe you'll not see clear text packets. > > [email protected] wrote: > > Hi again! > > > > I've resolved the first problem... It's a problem of mss and I fixed it > with > > this command : > > iptables -A FORWARD -p tcp --tcp-flags SYN,RST SYN -j TCPMSS --set-mss 1400 > > > > But I don't understand why certains ip headers are not encrypted. > > Here you can see packets captured by tcpdump between Zeus and Memphis : > > > > > > 14:52:05.997207 IP 192.168.1.2 > zeus: ESP(spi=0x026b1dc2,seq=0x224) > > 14:52:06.048469 IP zeus > 192.168.1.2: ESP(spi=0x0c58e1d2,seq=0x201) > > 14:52:06.048469 IP dns-abo-static-a.wanadoo.fr.domain > 192.168.1.2.32818: > > 40589 NXDomain 0/1/0 (119) > > 14:52:06.050011 IP 192.168.1.2 > zeus: ESP(spi=0x026b1dc2,seq=0x225) > > 14:52:06.117427 IP zeus > 192.168.1.2: ESP(spi=0x0c58e1d2,seq=0x202) > > 14:52:06.117427 IP dns-abo-static-a.wanadoo.fr.domain > 192.168.1.2.32818: > > 40590 1/2/2 PTR[|domain] > > 14:52:06.119071 IP zeus > 192.168.1.2: ESP(spi=0x0c58e1d2,seq=0x203) > > 14:52:06.119071 IP 64.12.26.57.5190 > 192.168.1.2.34641: . ack 187402029 > win > > 16384 > > 14:52:06.129232 IP 192.168.1.2 > zeus: ESP(spi=0x026b1dc2,seq=0x226) > > > > I can see several ip adress as if those packets were not encrypted! Where > is the > > problem? > > > > -------------------------------------------------------------- > > Old Message > > -------------------------------------------------------------- > > > > Hi all :-) > > > > I have a problem with my current configuration of ipsec. I'm using ipsec > with > > kernel 2.6 and racoon. I have two computers linked by wireless cards. The > first > > (192.168.1.1 Zeus) is connected to internet through a DSL modem and the > second > > (192.168.1.2 Memphis) is accessing internet through the first. I want with > > ipsec to encrypt all datas between the two computers. > > I can exchange data between the two computers and Memphis can access the > > internet but when I tried to download a big file, it didn't work although > it > > worked fine on Zeus. I've tried to change the MTU to 1300 but it changed > > nothing. > > I have another problem, when I exchanged data between Memphis and internet, > the > > ip header is not protected by ESP , I can see the source adress with > > tcpdump! > > > > Can somebody help me? Thanks in advance! > > Here is my configuration file for Zeus (it's nearly the same for Memphis) > > > > Setkey : > > > > #!/user/sbin/setkey -f > > flush; > > spdflush; > > > > spdadd 192.168.1.2/32 0.0.0.0/0 any -P out ipsec > > esp/tunnel/192.168.1.2-192.168.1.1/require; > > spdadd 0.0.0.0/0 192.168.1.2/32 any -P in ipsec > > esp/tunnel/192.168.1.1-192.168.1.2/require; > > > > Racoon.conf > > > > remote 192.168.1.1 > > { > > exchange_mode main; > > my_identifier asn1dn; > > peers_identifier asn1dn; > > > > certificate_type x509 "Memphis.public" "Memphis.private"; > > peers_certfile "Zeus.public"; > > proposal{ > > encryption_algorithm 3des; > > hash_algorithm sha1; > > authentication_method rsasig; > > dh_group modp1024; > > > > } > > > > } > > > > sainfo anonymous > > { > > pfs_group modp1024; > > lifetime time 2 min; > > encryption_algorithm 3des; > > authentication_algorithm hmac_md5; > > compression_algorithm deflate; > > } > > > > > > > > > > >