Bug 132832
| Summary: | ipsec malformed packet in tunnel mode with ah and esp | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 3 | Reporter: | benoit rovera <benoit.rovera-c> | ||||||
| Component: | kernel | Assignee: | David Miller <davem> | ||||||
| Status: | CLOSED WONTFIX | QA Contact: | |||||||
| Severity: | medium | Docs Contact: | |||||||
| Priority: | medium | ||||||||
| Version: | 3.0 | CC: | ckjohnson, petrides, riel | ||||||
| Target Milestone: | --- | ||||||||
| Target Release: | --- | ||||||||
| Hardware: | i686 | ||||||||
| OS: | Linux | ||||||||
| Whiteboard: | |||||||||
| Fixed In Version: | Doc Type: | Bug Fix | |||||||
| Doc Text: | Story Points: | --- | |||||||
| Clone Of: | Environment: | ||||||||
| Last Closed: | 2007-10-19 19:18:09 UTC | Type: | --- | ||||||
| Regression: | --- | Mount Type: | --- | ||||||
| Documentation: | --- | CRM: | |||||||
| Verified Versions: | Category: | --- | |||||||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |||||||
| Cloudforms Team: | --- | Target Upstream Version: | |||||||
| Embargoed: | |||||||||
| Attachments: |
|
||||||||
|
Description
benoit rovera
2004-09-17 16:26:36 UTC
This is also true of FC2 kernel 2.6.8-1.521 for ipsec tunnel mode. I have a packet trace and ipsec configuration if that would be helpful. Furthermore, I have proven with the packet trace that some packets are misaddressed. Specifically for a packet of the form: IP header1 | AH header | IP header2 | ESP The IP header1 has an incorrect destination address of the host in the remote tunneled subnet instead of the remote vpn partner, whereas IP header2 has the correct destination address of the remote vpn partner. For an host in local ipsec subnet contacting a web server in remote ipsec subnet the initial syn and response of syn,ack are tunnelled successfuly, but the encrypted ack goes out malformed, thus is never delivered. Created attachment 104342 [details]
ethereal trace of attempted tunnelled connection to a web server
Packet 11 exhibits the ipsec bug. Note the icmp response in packet 12 from
router due to the mis-addressed packet.
Created attachment 104343 [details]
Output of setkey -DP
Note VPN partner addresses of 169.244.85.2 and 169.244.32.130, and their
tunneled subnet scopes of 10.6.18.0/24 and 192.168.0.0/16 respectively.
This bug is filed against RHEL 3, which is in maintenance phase. During the maintenance phase, only security errata and select mission critical bug fixes will be released for enterprise products. Since this bug does not meet that criteria, it is now being closed. For more information of the RHEL errata support policy, please visit: http://www.redhat.com/security/updates/errata/ If you feel this bug is indeed mission critical, please contact your support representative. You may be asked to provide detailed information on how this bug is affecting you. |