RE: port bound SAs
From: Paul Moore <hidden>
Date: 2009-01-27 17:05:13
i did exactly that (in the original message) and it makes this test case work but as I point out a) it should not be necessary b) i get more SAs than I need c) i can no longer say that a SA is optional (this is an error in the pfkey/xfrm/racoon interface to combine two orthogonal concepts) d) I am not convinced that I have resolved all cases. Needs more testing -----Original Message----- From: Patrick McHardy [mailto:kaber@trash.net] Sent: Tuesday, January 27, 2009 9:01 AM To: Paul Moore Cc: David Miller; netdev@vger.kernel.org Subject: Re: port bound SAs Paul Moore wrote:
racoon if I look at the xfrm/pfkey code in the kernel it ignores any ports
sent
down by the IKE daemon in transport mode. I actually changed the
racoon
code to include the ports and it makes no difference
Assuming you're also using setkey, try adding "unique" to your policies.