Hello all!
I have a problem, something strange that i can't explain.
params:
my box: x.x.x.x
remote crypt-server: y.y.y.133
remote destination-server: y.y.y.136
ipsec tunnel init perfectly, i have this lines in my log:
Code:
INFO: IPsec-SA established: ESP/Tunnel x.x.x.133[0]->y.y.y.y[0] spi=9929892(0x9784a4)
INFO: IPsec-SA established: ESP/Tunnel y.y.y.y[0]->x.x.x.133[0] spi=1039267100(0x3df1f51c)
The problem is: when i try ping remote:
Code:
[root@gateway:~]# ping x.x.x.136
PING x.x.x.136 (x.x.x.136) 56(84) bytes of data.
--- x.x.x.136 ping statistics ---
1 packets transmitted, 0 received, 100% packet loss, time 0ms
i got this in tcpdump
Code:
[root@gateway:~]# tcpdump host x.x.x.133
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth0, link-type EN10MB (Ethernet), capture size 96 bytes
10:32:15.489284 IP y.y.y.y > x.x.x.133: ESP(spi=0x3df1f51c,seq=0xe), length 116
10:32:15.521198 IP x.x.x.133 > y.y.y.y: ESP(spi=0x009784a4,seq=0xe), length 116
setkey rules are:
Code:
spdadd x.x.x.x y.y.y.136 any -P out ipsec esp/tunnel/x.x.x.x-y.y.y.133/require;
spdadd y.y.y.136 x.x.x.x any -P in ipsec esp/tunnel/y.y.y.133-x.x.x.x/require;
Help, please.