(racoon 855) Re: Racoon NAT-T Transport Mode
Derek Atkins <[email protected]> Thu, 4 Nov 2004 20:51:05 -0500
| Newsgroups | gmane.network.ipv6.kame.racoon |
|---|---|
| Message-ID | <[email protected]> |
Quoting Michal Ludvig <[email protected]>: > On Thu, 4 Nov 2004, Emmanuel Dreyfus wrote: > > > Michal Ludvig <[email protected]> wrote: > > > > > IPsec-tools racoon doesn't support NAT-OA payload that is required for > > > transport mode byt the standard. It is quite some time since I wrote the > > > NAT-T support so I'm not sure how much work would it be to add it... > > > > Not that much, IMO. Implementing OA will also make possible to use > > multiple machines from behind a NAT. > > I doubt it will help on Linux. It is missing OA handling at all (you > can pass it to the kernel but the structure is never used). > > BTW Having multiple clients behind a NAT doesn't work in Tunnel mode? > But for Tunnel mode NAT-OA isn't transmitted anyway (as written in RFC). > > Michal Ludvig NAT-OA is ignored by the Linux Kernel because it internally recomputes (or, rather, just ignores) the checksum, so you don't need it. If it passes through the IPsec checks it marks the packet "checksum ok" so the IP address is not needed from the OA packet. The IKE daemon should still transmit (and accept) it, however. -derek -- Derek Atkins, SB '93 MIT EE, SM '95 MIT Media Laboratory Member, MIT Student Information Processing Board (SIPB) URL: http://web.mit.edu/warlord/ PP-ASEL-IA N1NWH [email protected] PGP key available