Re: ipsec site-to-site merge doar intr-un sens

Andrei-Florian Staicu <[email protected]>
Newsgroups gmane.org.user-groups.rlug.offtopic
Message-ID <CANK4U2rKaNONeO0ttiKqp7dhggycFVYYavDDBLL+g4Y8VnwgFw@mail.gmail.com>
Masina care e nat-ata nu are decat o interfata, aia privata. Si un tcpdump
la un ping dinpre aia nat-ata catre ailalata arata destul de bine:
root@S2:~# tcpdump -i any -nn -vvv udp port 4500
tcpdump: listening on any, link-type LINUX_SLL (Linux cooked), capture size
262144 bytes
22:35:00.430218 IP (tos 0x0, ttl 64, id 26417, offset 0, flags [DF], proto
UDP (17), length 160)
    10.200.1.2.4500 > 198.51.100.2.4500: [no cksum] UDP-encap:
ESP(spi=0xc2a72744,seq=0x2b), length 132
22:35:00.434225 IP (tos 0x0, ttl 57, id 65157, offset 0, flags [none],
proto UDP (17), length 160)
    198.51.100.2.4500 > 10.200.1.2.4500: [no cksum] UDP-encap:
ESP(spi=0xc769856e,seq=0x16), length 132

Dar cand incerc invers nu ajunge nici macar reqest-ul in 4500.

On Mon, Feb 6, 2017 at 10:33 PM Mihai Badici <[email protected]> wrote:

> On Monday 06 February 2017 20:24:52 Andrei-Florian Staicu wrote:
> > Nu prea pot sa controlez nat-ul, ca e un network de azure. Dar am crezut
> ca
> > chestia asta o rezolva nat-t, care cica e default de la strongswan 5
> > incoace.
> >
> Da, o rezolvă, dar nu-ti bagă si in traistă :)
> Dacă ambele interfeţe sunt pe virtuala ta, e de ajuns sa pui o regula de
> allow
> inainte de masquerade sau snat sau ce ai tu, nu conteaza ca e Azure.
> Nat-t iti impacheteaza totul in pachete udp pe portul ala 4500 sau cat e.
> Dar
> daca sursa si destinatia sunt deja alterate tot n-are cum sa mearga.
> Important
> e cu ce sursa ajung pachetele la engine-ul de ipsec, cu adresa privata sau
> cu
> cea publică.
> _______________________________________________
> Offtopic mailing list
> [email protected]
> http://lists.lug.ro/mailman/listinfo/offtopic
>
-- 
Beware of programmers who carry screwdrivers.
_______________________________________________
Offtopic mailing list
[email protected]
http://lists.lug.ro/mailman/listinfo/offtopic
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.