Réf. : Re: R if._:_Re:_IPv6_Linklocal_address_an d_IPSec_bug
[email protected] Fri, 19 Sep 2003 15:13:23 +0200
| Newsgroups | gmane.os.openbsd.ipv6 |
|---|---|
| Message-ID | <[email protected]> |
Hi,
You'll find here after a dump of my config.
I'm working on an update of the IPSec FAQ with an IPv6 chapter. Should
release
it next week.
Please note that ff13::1234:5678 are multicast IPv6 address with network
scope
('3') and works fine
when ff12::1234:5678 is the same address with a link local scope ('2') and
needs
a kernel patch.
Regards,
Sébastien Josset
sender configuration
----------------------------
#ipsecadm new esp -spi 1003 \
-src 3ffe:12::2 \
-dst ff13::1234:5678 \
-forcetunnel -enc blf -auth sha1 \
-key 1234567890123456789012345678901234567890 \
-authkey 1234567890123456789012345678901234567890
#ipsecadm flow -proto esp -dst ff13::1234:5678 -spi 1003 \
-addr \
3ffe:12::2/128 \
ff13::1234:5678/128 \
-out \
-require
receiver configuration
--------------------------
#ipsecadm new esp -spi 1003 \
-src 3ffe:12::2 \
-dst ff13::1234:5678 \
-forcetunnel -enc blf -auth sha1 \
-key 1234567890123456789012345678901234567890 \
-authkey 1234567890123456789012345678901234567890
#ipsecadm flow -proto esp -dst ff13::1234:5678 -spi 1003 \
-addr \
3ffe:12::2/128 \
ff13::1234:5678/128 \
-in \
-require
#netstat -rn
---------------
Routing tables
Internet:
Destination Gateway Flags Refs Use Mtu
Interface
10/8 link#1 UC 0 0 - fxp0
10.0.0.1 link#1 UHL 2 0 - fxp0
10.0.0.4 0:8:2:68:37:fe UHL 0 67 - lo0
11/8 10.0.0.1 UGS 0 0 - fxp0
12/8 10.0.0.1 UGS 0 0 - fxp0
127.0.0.1 127.0.0.1 UH 1 96 33224 lo0
Internet6:
Destination Gateway Flags
Refs
Use Mtu Interface
::1 ::1 UH
0
0 33224 lo0
3ffe:10::/64 link#1 UC
0
0 - fxp0
3ffe:10::1 link#1 UHL
1
0 - fxp0
3ffe:11::5 3ffe:10::1 UGHS
0
0 - fxp0
fe80::%fxp0/64 link#1 UC
0
0 - fxp0
fe80::%lo0/64 fe80::1%lo0 U
0
0 - lo0
ff01::/32 ::1 UC
0
0 - lo0
ff02::%fxp0/32 link#1 UC
0
0 - fxp0
ff02::%lo0/32 ::1 UC
0
0 - lo0
ff13::1234:5678 3ffe:10::4 UHS
0
0 - fxp0
Encap:
Source Port Destination Port Proto
SA(Address/Proto/Type/Direction)
3ffe:12::2/128 0 ff13::1234:5678/128
0 0 ff13::1234:5678/50/require/out
#cat /kern/ipsec
----------------
Hashmask: 31, policy entries: 1
SPI = 00001003, Destination = ff13::1234:5678, Sproto = 50
Established 580 seconds ago
Source = 3ffe:0012::0002
Flags (00001000) = <tunneling>
Crypto ID: 1
xform = <IPsec ESP>
Encryption = <Blowfish>
Authentication = <HMAC-SHA1>
0 bytes processed by this SA
Expirations:
(none)
#ipsecadm show
--------------
sadb_dump: satype unspec vers 2 len 26 seq 1 pid 21065
sa: spi 0x00001003 auth hmac-sha1 enc blowfish
state larval replay 0 flags 4
lifetime_cur: alloc 0 bytes 0 add 1063982868 first 0
address_src: 3ffe:12::2
address_dst: ff13::1234:5678
key_auth: bits 160: 1234567890123456789012345678901234567890
key_encrypt: bits 160: 1234567890123456789012345678901234567890
[email protected] (Jun-ichiro itojun Hagino) on 17/09/2003 01:34:53
Pour : [email protected]
cc : (ccc : Sebastien Josset/ALCATEL-SPACE)
Objet : Re: R
if._:_Re:_IPv6_Linklocal_address_and_IPSec_bug
> I tested an ESP SA with blowfish/sha1 transform.
> Best regards,
would you mind sending your ipsecadm(8) configs?
itojun
ALCATEL SPACE
Research Department/Advanced Telecom Satellite Systems
Tel : +33 (0)53435 5104 / Fax : +33 (0)53435 5560
Porte : W218 / E-Mail : [email protected]
ALCATEL SPACE