(racoon 855) Re: Racoon NAT-T Transport Mode

Derek Atkins <[email protected]> Thu, 4 Nov 2004 20:51:05 -0500
Newsgroups gmane.network.ipv6.kame.racoon
Message-ID <[email protected]>
Quoting Michal Ludvig <[email protected]>:

> On Thu, 4 Nov 2004, Emmanuel Dreyfus wrote:
> 
> > Michal Ludvig <[email protected]> wrote:
> > 
> > > IPsec-tools racoon doesn't support NAT-OA payload that is required for
> > > transport mode byt the standard. It is quite some time since I wrote the
> > > NAT-T support so I'm not sure how much work would it be to add it...
> > 
> > Not that much, IMO. Implementing OA will also make possible to use
> > multiple machines from behind a NAT.
> 
> I doubt it will help on Linux. It is missing OA handling at all (you 
> can pass it to the kernel but the structure is never used).
> 
> BTW Having multiple clients behind a NAT doesn't work in Tunnel mode? 
> But for Tunnel mode NAT-OA isn't transmitted anyway (as written in RFC).
> 
> Michal Ludvig

NAT-OA is ignored by the Linux Kernel because it internally recomputes (or,
rather, just ignores) the checksum, so you don't need it.  If it passes through
the IPsec checks it marks the packet "checksum ok" so the IP address is not
needed from the OA packet.

The IKE daemon should still transmit (and accept) it, however.

-derek 
-- 
       Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory
       Member, MIT Student Information Processing Board  (SIPB)
       URL: http://web.mit.edu/warlord/    PP-ASEL-IA     N1NWH
       [email protected]                        PGP key available