[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
- To: misc_(_at_)_openbsd_(_dot_)_org
- Subject: isakmpd problem?
- From: asd asd <pocketticket_(_at_)_yahoo_(_dot_)_com_(_dot_)_au>
- Date: Mon, 7 May 2001 08:12:15 +1000 (EST)
i have two 2.8 boxes, one generic kernel another with
a stripped down generic. After reading
(Subject: How-To: 2.8-stable *and* isakmpd from
jason_(_at_)_macrosys_(_dot_)_com) i cvs up-ed
the isakmpd sources, compiled and installed them.
Now i do have ping between public addrs of the boxes,
do have a proper auth (almost there are no error
messages), and routes like this are created:
# netstat -rnf encap
Source Port Destination Port
10.0.0/24 0 172.16/16 0 0
172.16/16 0 10.0.0/24 0 0
The problem seems to be the same: esp traffic goes
one side to another but it doesn't seems to reach the
internal network, ie a ping from 10.0.0.3 to
generates esp traffic that strikes on tcpdump proto
on the other side and 172.16.0.1 doesn't get the
request. Same on both directions.
ipf rules doesn't restrict any traffic.
I'm using a copy of the east-west config files with
ip addresses changed to fit my needs; the policy file
Comment: This policy accepts ESP SAs from a ...
What can i do now?
- It's time you had your business online!
Visit your host, monkey.org