(racoon 850) RE: Racoon NAT-T Transport Mode
"David Herselman" <[email protected]> Thu, 4 Nov 2004 18:22:46 +0200
| Newsgroups | gmane.network.ipv6.kame.racoon |
|---|---|
| Organization | Syrex Intranets |
| Message-ID | <[email protected]> |
I assume that this NAT-T patch would resolve the following problem I'm currently experiencing when trying to connect in the following scenario: 192.168.1.97 --- 192.168.1.1 [Gateway] 165.165.129.17 -------------- 165.165.174.164 Windows XP Racoon Oct 28 22:50:38 unix-03 racoon: INFO: isakmp.c:903:isakmp_ph1begin_r(): respond new phase 1 negotiation: 165.165.129.17[500]<=>165.165.174.164[500] Oct 28 22:50:38 unix-03 racoon: INFO: isakmp.c:908:isakmp_ph1begin_r(): begin Identity Protection mode. Oct 28 22:50:38 unix-03 racoon: INFO: vendorid.c:128:check_vendorid(): received Vendor ID: MS NT5 ISAKMPOAKLEY Oct 28 22:50:39 unix-03 racoon: INFO: isakmp.c:2443:log_ph1established(): ISAKMP-SA established 165.165.129.17[500]-165.165.174.164[500] spi:8b96913a4b030412:75663d7f02b48ad5 Oct 28 22:50:39 unix-03 racoon: INFO: isakmp.c:1058:isakmp_ph2begin_r(): respond new phase 2 negotiation: 165.165.129.17[0]<=>165.165.174.164[0] Oct 28 22:50:39 unix-03 racoon: INFO: isakmp_quick.c:2016:get_proposal_r(): no policy found, try to generate the policy : 192.168.1.97/32[1701] 165.165.129.17/32[1701] proto=udp dir=in # Using 192.168.1.97 instead of NAT address... Oct 28 22:50:39 unix-03 racoon: INFO: pfkey.c:1127:pk_recvupdate(): IPsec-SA established: ESP/Transport 165.165.174.164->165.165.129.17 spi=214326860(0xcc65e4c) Oct 28 22:50:39 unix-03 racoon: INFO: pfkey.c:1348:pk_recvadd(): IPsec-SA established: ESP/Transport 165.165.129.17->165.165.174.164 spi=400835875(0x17e44523) Oct 28 22:50:39 unix-03 racoon: ERROR: pfkey.c:1941:pk_recvspdupdate(): such policy does not already exist: 192.168.1.97/32[1701] 165.165.129.17/32[1701] proto=udp dir=in Oct 28 22:50:39 unix-03 racoon: ERROR: pfkey.c:1941:pk_recvspdupdate(): such policy does not already exist: 165.165.129.17/32[1701] 192.168.1.97/32[1701] proto=udp dir=out # Using 192.168.1.97 instead of NAT address... Oct 28 22:50:46 unix-03 racoon: INFO: isakmp_inf.c:987:purge_ipsec_spi(): purged IPsec-SA proto_id=ESP spi=400835875. Oct 28 22:50:46 unix-03 racoon: INFO: isakmp_inf.c:885:purge_isakmp_spi(): purged ISAKMP-SA proto_id=ISAKMP spi=8b96913a4b030412:75663d7f02b48ad5. Oct 28 22:50:47 unix-03 racoon: INFO: isakmp.c:1593:isakmp_ph1delete(): ISAKMP-SA deleted 165.165.129.17[500]-165.165.174.164[500] spi:8b96913a4b030412:75663d7f02b48ad5 Syrex Intranets - Customised Solutions David Herselman Systems Engineer cell +27 (0)82 784 7222 tel +27 (0)86 11 syrex (79739) fax +27 (0)86 12 syrex (79739) 27 7th avenue parktown north 2193 email [email protected] www.syrex.co.za -----Original Message----- From: [email protected] [mailto:[email protected]] On Behalf Of Emmanuel Dreyfus Sent: 03 November 2004 11:57 PM To: [email protected] Subject: (racoon 849) Re: Racoon NAT-T Transport Mode Miles Nordin <[email protected]> wrote: > manu is working on one for NetBSD. I don't know the status. > http://mail-index.netbsd.org/tech-kern/2004/09/30/0006.html A possible US patent on NAT-T prevented me from committing it into the NetBSD tree. Someone is currently investigating if this can be safely committed. In the meantime, anyone living in a (software patent) free country can use it. Here is the latest patch: http://ftp.espci.fr/shadow/manu/nat-t.patch I don't know if it works with transport mode, though. I see no reason why it wouldn't. I use it in tunnel mode. > It sounds like he is maybe not using the default racoon that comes > with KAME? I use ipsec-tools racoon. -- Emmanuel Dreyfus Il y a 10 sortes de personnes dans le monde: ceux qui comprennent le binaire et ceux qui ne le comprennent pas. [email protected]