[Bug 346211] New: racoon (novell-ipsec-tools pkg) can build tunnels but no traffic gets through
https://bugzilla.novell.com/show_bug.cgi?id=346211 Summary: racoon (novell-ipsec-tools pkg) can build tunnels but no traffic gets through Product: SUSE Linux 10.1 Version: Final Platform: x86-64 OS/Version: SLED 10 Status: NEW Severity: Major Priority: P5 - None Component: Security AssignedTo: security-team@suse.de ReportedBy: david.mattes@boeing.com QAContact: qa@suse.de CC: stingleff@novell.com, bili@novell.com Found By: Customer I am using novell-ipsec-tools, along with turnpike, to build VPN tunnels. VPN tunnels have been and are still successfully established but VPN traffic stopped flowing with novell-ipsec-tools-0.6.3-26.14 (SLED10SP1) as a regression from novell-ipsec-tools-0.6.3-26.4 (SLED10). When I connect with 26.4 (when it works) the relevant entries in syslog are: racoon: INFO: IPsec-SA established: ESP/Tunnel 10.0.0.1[0]->192.168.1.150[0] racoon: INFO: IPsec-SA established: ESP/Tunnel 192.168.1.150[0]->10.0.0.1[0] And the tunnel works fine. But when I connect with 26.14 these change to: racoon: INFO: IPsec-SA established: ESP/Tunnel 10.0.0.1[500]->192.168.1.150[500] racoon: INFO: IPsec-SA established: ESP/Tunnel 192.168.1.150[500]->10.0.0.1[500] And then when I try to send data through the tunnel I get a constant (~1/sec) stream of the following: racoon: DEBUG: KA: 192.168.1.150[500]->10.0.0.1[500] racoon: DEBUG: sockname 192.168.1.150[500] racoon: DEBUG: send packet from 192.168.1.150[500] racoon: DEBUG: send packet to 10.0.0.1[500] racoon: DEBUG: src4 192.168.1.150[500] racoon: DEBUG: dst4 10.0.0.1[500] racoon: DEBUG: 1 times of 1 bytes message will be sent to 10.0.0.1[500] racoon: DEBUG: ff The only difference I can see is the change from ipaddr[0] to ipaddr[500], going from version 26.4 to version 26.14. What is the [500], and why did that change between the two versions? Is this a config option? Thanks! -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c1
--- Comment #1 from Li Bin
racoon: DEBUG: KA: 192.168.1.150[500]->10.0.0.1[500] racoon: DEBUG: sockname 192.168.1.150[500] racoon: DEBUG: send packet from 192.168.1.150[500] racoon: DEBUG: send packet to 10.0.0.1[500] racoon: DEBUG: src4 192.168.1.150[500] racoon: DEBUG: dst4 10.0.0.1[500] racoon: DEBUG: 1 times of 1 bytes message will be sent to 10.0.0.1[500] racoon: DEBUG: ff These packets just were the KeepAlive package.
-- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=346211
Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
Thomas Biege
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c2
Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c3
--- Comment #3 from Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
Harald Mueller-Ney
https://bugzilla.novell.com/show_bug.cgi?id=346211
User david.mattes@boeing.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c4
--- Comment #4 from David Mattes
https://bugzilla.novell.com/show_bug.cgi?id=346211
User david.mattes@boeing.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c5
--- Comment #5 from David Mattes
https://bugzilla.novell.com/show_bug.cgi?id=346211
User david.mattes@boeing.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c6
David Mattes
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c7
--- Comment #7 from Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c8
Li Bin
From your log file, I found it's ok, not a bug.
If you have any problem contact me. If not, I'll closed this bug. Thanks! -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=346211
User david.mattes@boeing.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c9
--- Comment #9 from David Mattes
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c10
--- Comment #10 from Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c11
--- Comment #11 from Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
User uwedr@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c13
Uwe Drechsel
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c14
--- Comment #14 from Li Bin
openSUSE is not covered by L3 support, which is needed here. A fix is going to be released as Maintenance Update for SUSE Linux Enterprise Desktop.
I assume you need the fix for SLED, right?
Yes, and also I've submit the new package to STABLE for next release for OpenSUSE 11 and SLED10 SP2. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=346211 Bug 346211 depends on bug 339674, which changed state. Bug 339674 Summary: novell-nortelplugins causes racoon crash with split tunnel https://bugzilla.novell.com/show_bug.cgi?id=339674 What |Old Value |New Value ---------------------------------------------------------------------------- Status|NEEDINFO |RESOLVED Resolution| |FIXED -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c15
Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c18
Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
User stingleff@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c19
--- Comment #19 from Sam Tingleff
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c20
--- Comment #20 from Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
User stingleff@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c21
--- Comment #21 from Sam Tingleff
https://bugzilla.novell.com/show_bug.cgi?id=346211
User bili@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c22
Li Bin
https://bugzilla.novell.com/show_bug.cgi?id=346211
User gekker@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c23
Gary Ekker
https://bugzilla.novell.com/show_bug.cgi?id=346211
User gekker@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c24
Gary Ekker
https://bugzilla.novell.com/show_bug.cgi?id=346211
User ast@novell.com added comment
https://bugzilla.novell.com/show_bug.cgi?id=346211#c30
--- Comment #30 from Anja Stock
participants (1)
-
bugzilla_noreply@novell.com