Re: ipv6 ipsec
"Todd T. Fries" <[email protected]> Tue, 17 May 2005 15:47:35 -0500
| Newsgroups | gmane.os.openbsd.ipv6 |
|---|---|
| Organization | Free Daemon Consulting, LLC |
| Message-ID | <[email protected]> |
I use OpenBSD regularly to do IPSec using v4 transport and v4 inside the tunnel as well as v6 inside the tunnel using OpenBSD to OpenBSD. No issues with this scenario. I hope to learn enough to track down the reason why the v6 transport and v6 tunnel does not work, however. On 2005-05-17 at 22:15 +0200, [email protected] wrote: > hello, > > i have configured a szenario with multiple road warrior's and PSK with isakmpd. > the tunnelendpoints are ipv4 hosts, the networks inside the ipsec-tunnel are > ipv6. when i try to establish a tunnel between rw and vpn-gate isakmpd reports > the error: > > Default pf_key_v2_write: writev (3, 0x8141500, 5) failed: Invalid argument > it seems, that the iskmpd inserts SAD rules, but no SPD rules > > (the error is reported at rw and vpn-gate) > you can find the complete logfiles at: > > rw http://www.ipv6.uni-leipzig.de/clog > gate http://www.ipv6.uni-leipzig.de/slog > > > when I try a similar configuration with ipv4-networks inside the tunnel > everything works well. > is there any restriction in isakmpd or the netbsd kernel that forbits such a > configuration? > > > testet systems: > NetBSD 2.0F / NetBSD 2.99.9 / NetBSD 3.99.3 > isakmpd-20030903nb4 > > I have already asked about the problem the netbsd and kame maillinglist > but they told me to ask the openbsd community because they develop > isakmpd. > > thank you for your efforts > Uwe > -- Todd Fries .. [email protected] _____________________________________________ | \ 1.636.410.0632 (voice) | Free Daemon Consulting, LLC \ 1.405.227.9094 (voice) | http://FreeDaemonConsulting.com \ 1.866.792.3418 (FAX) | "..in support of free software solutions." \ 1.700.227.9094 (IAXTEL) | \ 250797 (FWD) \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ 37E7 D3EB 74D0 8D66 A68D B866 0326 204E 3F42 004A http://todd.fries.net/pgp.txt