(racoon 850) RE: Racoon NAT-T Transport Mode

"David Herselman" <[email protected]> Thu, 4 Nov 2004 18:22:46 +0200
Newsgroups gmane.network.ipv6.kame.racoon
Organization Syrex Intranets
Message-ID <[email protected]>
I assume that this NAT-T patch would resolve the following problem I'm
currently experiencing when trying to connect in the following scenario:

192.168.1.97  --- 192.168.1.1 [Gateway] 165.165.129.17   --------------
165.165.174.164
Windows XP
Racoon

Oct 28 22:50:38 unix-03 racoon: INFO: isakmp.c:903:isakmp_ph1begin_r():
respond new phase 1 negotiation: 165.165.129.17[500]<=>165.165.174.164[500]
Oct 28 22:50:38 unix-03 racoon: INFO: isakmp.c:908:isakmp_ph1begin_r():
begin Identity Protection mode.
Oct 28 22:50:38 unix-03 racoon: INFO: vendorid.c:128:check_vendorid():
received Vendor ID: MS NT5 ISAKMPOAKLEY
Oct 28 22:50:39 unix-03 racoon: INFO: isakmp.c:2443:log_ph1established():
ISAKMP-SA established 165.165.129.17[500]-165.165.174.164[500]
spi:8b96913a4b030412:75663d7f02b48ad5
Oct 28 22:50:39 unix-03 racoon: INFO: isakmp.c:1058:isakmp_ph2begin_r():
respond new phase 2 negotiation: 165.165.129.17[0]<=>165.165.174.164[0]
Oct 28 22:50:39 unix-03 racoon: INFO: isakmp_quick.c:2016:get_proposal_r():
no policy found, try to generate the policy : 192.168.1.97/32[1701]
165.165.129.17/32[1701] proto=udp dir=in

# Using 192.168.1.97 instead of NAT address...

Oct 28 22:50:39 unix-03 racoon: INFO: pfkey.c:1127:pk_recvupdate(): IPsec-SA
established: ESP/Transport 165.165.174.164->165.165.129.17
spi=214326860(0xcc65e4c)
Oct 28 22:50:39 unix-03 racoon: INFO: pfkey.c:1348:pk_recvadd(): IPsec-SA
established: ESP/Transport 165.165.129.17->165.165.174.164
spi=400835875(0x17e44523)
Oct 28 22:50:39 unix-03 racoon: ERROR: pfkey.c:1941:pk_recvspdupdate(): such
policy does not already exist: 192.168.1.97/32[1701] 165.165.129.17/32[1701]
proto=udp dir=in
Oct 28 22:50:39 unix-03 racoon: ERROR: pfkey.c:1941:pk_recvspdupdate(): such
policy does not already exist: 165.165.129.17/32[1701] 192.168.1.97/32[1701]
proto=udp dir=out

# Using 192.168.1.97 instead of NAT address...

Oct 28 22:50:46 unix-03 racoon: INFO: isakmp_inf.c:987:purge_ipsec_spi():
purged IPsec-SA proto_id=ESP spi=400835875.
Oct 28 22:50:46 unix-03 racoon: INFO: isakmp_inf.c:885:purge_isakmp_spi():
purged ISAKMP-SA proto_id=ISAKMP spi=8b96913a4b030412:75663d7f02b48ad5.
Oct 28 22:50:47 unix-03 racoon: INFO: isakmp.c:1593:isakmp_ph1delete():
ISAKMP-SA deleted 165.165.129.17[500]-165.165.174.164[500]
spi:8b96913a4b030412:75663d7f02b48ad5


Syrex Intranets - Customised Solutions

	David Herselman
	Systems Engineer
 	
	cell	 +27 (0)82 784 7222
	tel	 +27 (0)86 11 syrex (79739)
	fax	 +27 (0)86 12 syrex (79739)
	27 7th avenue parktown north 2193
	email [email protected]
	www.syrex.co.za


-----Original Message-----
From: [email protected] [mailto:[email protected]] On Behalf Of
Emmanuel Dreyfus
Sent: 03 November 2004 11:57 PM
To: [email protected]
Subject: (racoon 849) Re: Racoon NAT-T Transport Mode

Miles Nordin <[email protected]> wrote:

> manu is working on one for NetBSD.  I don't know the status.   
>  http://mail-index.netbsd.org/tech-kern/2004/09/30/0006.html

A possible US patent on NAT-T prevented me from committing it into the
NetBSD tree. Someone is currently investigating if this can be safely
committed.

In the meantime, anyone living in a (software patent) free country can use
it. Here is the latest patch: 
http://ftp.espci.fr/shadow/manu/nat-t.patch

I don't know if it works with transport mode, though. I see no reason why it
wouldn't. I use it in tunnel mode.
 
> It sounds like he is maybe not using the default racoon that comes 
> with KAME?

I use ipsec-tools racoon. 

--
Emmanuel Dreyfus
Il y a 10 sortes de personnes dans le monde: ceux qui comprennent le binaire
et ceux qui ne le comprennent pas.
[email protected]