Networking Forums

Networking Forums > Computer Networking > Linux Networking > IPSec Fallback mechanism subnet/supernet

Reply
Thread Tools Display Modes

IPSec Fallback mechanism subnet/supernet

 
 
anshul makkar
Guest
Posts: n/a

 
      01-09-2008, 03:15 AM
Hi,

I established two IPSEC tunnels terminating at one hub.
Configuration :
1st tunnel : right subnet as 192.168.4.0/24
2nd tunnel: right subnet as 192.168.0.0/16

Both the tunnels have same gateway as 172.16.28.108

I am using freeswan code.

Now what I am observing is that, if I disable the 192.168.4.0/24
tunnel, and send ping request to 192.168.4.1, the ICMP IPSEC SA is
negotiated for 2nd tunnel (supernet one which is already correctly
established.). Why this is happening.

Further, on continuous pinging (to machine on network 192.168.4.0/24),
a new IPSEC SA (for tunnel 192.168.0.0/26) is negotiated on every
request.

On debugging I found that when I disable a perticular tunnel, the path
corresponding to it is marked as trapped. Now klips capture the
outbound packets on the trapped path and tries to send it through
another closest matched active path. Thus in this scenrio, klips is
capturing the outbound packets destined for 192.168.4.0/24 subnet and
is trying to transfer it through 192.168.0.0/16. Is my inference
correct.

If this is the default behavior, then why IPSEC SA is being
renegotiated for every outbound ICMP packet. (IPSEC SA should be
established once and then used for every evey ping request)

Please if you have any hint or refernce then please do share it .

Thanking You
Anshul Makkar
 
Reply With Quote
 
 
 
 
anshul makkar
Guest
Posts: n/a

 
      01-11-2008, 04:21 AM
Hi,

Please reply. I am stuck.

Thanks
Anshul Makkar


On Jan 9, 9:15 am, anshul makkar <anshulmak...@gmail.com> wrote:
> Hi,
>
> I established two IPSEC tunnels terminating at one hub.
> Configuration :
> 1st tunnel : right subnet as 192.168.4.0/24
> 2nd tunnel: right subnet as 192.168.0.0/16
>
> Both the tunnels have same gateway as 172.16.28.108
>
> I am using freeswan code.
>
> Now what I am observing is that, if I disable the 192.168.4.0/24
> tunnel, and send ping request to 192.168.4.1, the ICMP IPSEC SA is
> negotiated for 2nd tunnel (supernet one which is already correctly
> established.). Why this is happening.
>
> Further, on continuous pinging (to machine on network 192.168.4.0/24),
> a new IPSEC SA (for tunnel 192.168.0.0/26) is negotiated on every
> request.
>
> On debugging I found that when I disable a perticular tunnel, the path
> corresponding to it is marked as trapped. Now klips capture the
> outbound packets on the trapped path and tries to send it through
> another closest matched active path. Thus in this scenrio, klips is
> capturing the outbound packets destined for 192.168.4.0/24 subnet and
> is trying to transfer it through 192.168.0.0/16. Is my inference
> correct.
>
> If this is the default behavior, then why IPSEC SA is being
> renegotiated for every outbound ICMP packet. (IPSEC SA should be
> established once and then used for every evey ping request)
>
> Please if you have any hint or refernce then please do share it .
>
> Thanking You
> Anshul Makkar


 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Strange blog-comment URL 'mechanism'? no.top.post@gmail.com Linux Networking 14 12-01-2011 12:25 PM
DHCP Superscope/SuperNet wrathe@cablespeed.com Windows Networking 3 08-23-2005 07:53 PM
Subnet, supernet and cidr calculator Clive Network Routers 3 11-03-2004 04:03 PM
IGMP report suppression mechanism muteki Linux Networking 0 08-02-2004 11:05 PM
supernet/subnet + NAT ASiF Linux Networking 6 11-12-2003 02:01 AM



1 2 3 4 5 6 7 8 9 10 11