Thread (31 messages) 31 messages, 4 authors, 2009-02-25

RE: port bound SAs

From: Paul Moore <hidden>
Date: 2009-01-27 17:05:13

i did exactly that (in the original message) and it makes this test case
work but as I point out

a) it should not be necessary 
b) i get more SAs than I need
c) i can no longer say that a SA is optional (this is an error in the
pfkey/xfrm/racoon interface to combine two orthogonal concepts)
d) I am not convinced that I have resolved all cases. Needs more testing

-----Original Message-----
From: Patrick McHardy [mailto:kaber@trash.net] 
Sent: Tuesday, January 27, 2009 9:01 AM
To: Paul Moore
Cc: David Miller; netdev@vger.kernel.org
Subject: Re: port bound SAs

Paul Moore wrote:
racoon

if I look at the xfrm/pfkey code in the kernel it ignores any ports
sent
down by the IKE daemon in transport mode. I actually changed the
racoon
code to include the ports and it makes no difference
Assuming you're also using setkey, try adding "unique" to your policies.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help