LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 06-14-2012, 11:54 AM   #1
Nemus
Member
 
Registered: Apr 2007
Distribution: Fedora/Ubuntu
Posts: 63

Rep: Reputation: 15
Openswan and SSL not sending AWK for one tunnel.


I have two tunnels setup and both have SA established.

The issue I am having is that the TCP connection on the server side is dropping the packets and not sending the AWK for tunnel A but the same connection for tunnel B works perfectly.

As you can see in the tcpdump.

Configuration is identical and I cannot figure out why it works in one place but not the other.

What would I need to check to solve this issue?

Could this be a MTU problem if so how?

Why would the server not send an ACK?

Could it be due to the /31 subnet on the other side is using?

Any help or ideas or guesses are welcome I have run out of ideas.


18:21:15.156533 IP x.x.27.18 > ne: ESP(spi=0x329696e7,seq=0xe), length 100
18:21:15.156619 IP x.x.31.21.13973 > ne.https: Flags [S], seq 589056160, win 61440, options [mss 1380,nop,wscale 0,nop,nop,TS val 9360945 ecr 0], length 0
18:21:16.171512 IP x.x.27.18 > ne: ESP(spi=0x329696e7,seq=0xf), length 100
18:21:16.171590 IP x.x.31.21.13973 > ne.https: Flags [S], seq 589056160, win 61440, options [mss 1380,nop,wscale 0,nop,nop,TS val 9360948 ecr 0], length 0
18:21:23.701551 IP x.x.27.18 > ne: ESP(spi=0x329696e7,seq=0x10), length 100
18:21:23.701634 IP x.x.31.21.13973 > ne.https: Flags [S], seq 589056160, win 61440, options [mss 1380,nop,wscale 0,nop,nop,TS val 9360963 ecr 0], length 0
18:28:03.391500 IP x.x.27.18 > ne: ESP(spi=0x329696e7,seq=0x19), length 84
18:28:03.391569 IP x.x.27.21.17427 > ne.https: Flags [R], seq 0, win 0, length 0


config setup
# Debug-logging controls: "none" for (almost) none, "all" for lots.
# klipsdebug=none
# plutodebug="control parsing"
# For Red Hat Enterprise Linux and Fedora, leave protostack=netkey
protostack=netkey
nat_traversal=yes
virtual_private=
oe=off
# Enable this if you see "failed to find any available worker"
nhelpers=0


conn a
type=tunnel
authby = secret
left = x.x.8.81
leftsubnet=x.x.8.81/32
leftsourceip = x.x.8.81
right= x.x.27.2
rightid =x.x.x.x
rightsubnets= {x.x.x.21/32,x.x.x.20/31}
esp=aes-256-sha1
ike="aes256-sha1-modp1024"
keyexchange = ike
pfs = no
auto = start
aggrmode=no
ikelifetime=86400s
lifetime=3600s

conn b
type=tunnel
authby = secret
left = x.x.8.81
leftsubnet =x.x.8.81/32
leftsourceip = x.x.8.81
right= x.x.x.x
rightid=x.x.x.x
rightsubnets= {x.x.x.x/32,x.x.x.x/32,x.x.x.40/32}
esp=aes256-sha1
ike="aes256-sha1-modp1024"
keyexchange = ike
pfs = no
auto = start
aggrmode=no
ikelifetime=86400s
lifetime=3600s

Last edited by Nemus; 06-14-2012 at 12:35 PM.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SSH on an IPsec tunnel with Openswan freezes aixarat Linux - Networking 2 03-25-2009 02:18 AM
Help using SSL tunnel rockmanchile Debian 1 05-22-2007 12:18 PM
Openswan/Cisco PIX: NATting a VPN Tunnel SnotRocket Linux - Networking 1 01-28-2007 09:13 PM
OpenSWAN - IPSec tunnel drops dieduster Linux - Networking 0 12-17-2006 10:07 AM
SSL Tunnel Squid engnet Linux - Security 1 02-21-2006 07:02 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:37 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration