I'm not sure if this is a KAME bug or an ipf misconfiguration, so I'm
starting here.

I've recently gone on a rash of IPSec/ipf installs.  Everything works great
and perfect, once I understood it, and knew which interfaces to filter for
what.

I've just finished setting up a IPSec tunnel between two 4.8-STABLE hosts
that is having oddness.  Tunnel initation from point B to A works fine, but
from point A to B is broken.

Host A has two external IP addresses -- 10.0.0.1 and 10.0.1.1.
Host A has two external subnets -- 192.168.0.0/29 and 192.168.1.0/30, being
routed to the two external addresses respectively.
All of 192.168.0.0/29 is aliased to the same interface as 10.0.0.1.
All of 192.168.1.0/30 is aliased to the same interface as 10.0.1.1.
Host A has one internal subnet -- 172.23.0.0/24

Host B has one external IP address -- 172.16.0.1.
Host B has a backup IP address that is not of concern (yet).
Host B has one internal subnet -- 172.23.1.0/24.

The IPSec configuration is set up so that the tunnel is from 192.168.0.2 to
172.16.0.1, the tunneled subnets being the two internal subnets.

If I initiate the tunnel from Host B, everything works fine.  If I initiate
the tunnel from Host A (ping -S 172.23.0.1 172.23.1.1), then Host B sees the
incoming tunnel endpoint as 10.0.0.1, claims no configuration, and dies.

So my question is: is it possible that any of my ipnat mappings are causing
troubles with this?  Or is it most definitely racoon that's picking the
wrong IP address to source from on Host A (yes, I've configured it to only
listen on 192.168.0.2)?  I wouldn't think that my map statements would cause
problems -- they're only for 172.23.0.0/24.

Help?

Reply via email to