I'm not sure if this is a KAME bug or an ipf misconfiguration, so I'm starting here.
I've recently gone on a rash of IPSec/ipf installs. Everything works great and perfect, once I understood it, and knew which interfaces to filter for what. I've just finished setting up a IPSec tunnel between two 4.8-STABLE hosts that is having oddness. Tunnel initation from point B to A works fine, but from point A to B is broken. Host A has two external IP addresses -- 10.0.0.1 and 10.0.1.1. Host A has two external subnets -- 192.168.0.0/29 and 192.168.1.0/30, being routed to the two external addresses respectively. All of 192.168.0.0/29 is aliased to the same interface as 10.0.0.1. All of 192.168.1.0/30 is aliased to the same interface as 10.0.1.1. Host A has one internal subnet -- 172.23.0.0/24 Host B has one external IP address -- 172.16.0.1. Host B has a backup IP address that is not of concern (yet). Host B has one internal subnet -- 172.23.1.0/24. The IPSec configuration is set up so that the tunnel is from 192.168.0.2 to 172.16.0.1, the tunneled subnets being the two internal subnets. If I initiate the tunnel from Host B, everything works fine. If I initiate the tunnel from Host A (ping -S 172.23.0.1 172.23.1.1), then Host B sees the incoming tunnel endpoint as 10.0.0.1, claims no configuration, and dies. So my question is: is it possible that any of my ipnat mappings are causing troubles with this? Or is it most definitely racoon that's picking the wrong IP address to source from on Host A (yes, I've configured it to only listen on 192.168.0.2)? I wouldn't think that my map statements would cause problems -- they're only for 172.23.0.0/24. Help?
