Re: Route modified dynamically

2010-03-12 Thread Claudio Jeker
On Fri, Mar 12, 2010 at 03:30:14PM +0100, Massimo Lusetti wrote: > On Fri, 12 Mar 2010 14:55:51 +0100 > Claudio Jeker wrote: > > > > > Wow that's a strange flag combo. Why is S & M set together? > > > > Hmm. Another strange routing thing I need to have a loot at. > > > > Most probably the cloning

Re: Route modified dynamically

2010-03-12 Thread Massimo Lusetti
On Fri, 12 Mar 2010 14:55:51 +0100 Claudio Jeker wrote: > > > Wow that's a strange flag combo. Why is S & M set together? > > > Hmm. Another strange routing thing I need to have a loot at. > > > Most probably the cloning is done wrong. > > > > Hmm, does it have to be cloned? Couldn't this be the

Re: Route modified dynamically

2010-03-12 Thread Claudio Jeker
On Fri, Mar 12, 2010 at 10:54:43AM +, Stuart Henderson wrote: > On 2010-03-12, Claudio Jeker wrote: > > On Fri, Mar 12, 2010 at 12:28:33AM +, Stuart Henderson wrote: > >> On 2010-03-10, Massimo Lusetti wrote: > >> > Hi misc, > >> > I got a 4.5 box which act as a perimeter ipsec routing

Re: Route modified dynamically

2010-03-12 Thread Stuart Henderson
On 2010-03-12, Claudio Jeker wrote: > On Fri, Mar 12, 2010 at 12:28:33AM +, Stuart Henderson wrote: >> On 2010-03-10, Massimo Lusetti wrote: >> > Hi misc, >> > I got a 4.5 box which act as a perimeter ipsec routing gateway, it >> > has 682 flow (by ipsecctl -sf | wc -l). >> > >> > Some of

Re: Route modified dynamically

2010-03-12 Thread Massimo Lusetti
On Fri, 12 Mar 2010 01:43:39 +0100 Claudio Jeker wrote: > On Fri, Mar 12, 2010 at 12:28:33AM +, Stuart Henderson wrote: > > On 2010-03-10, Massimo Lusetti wrote: > > > Hi misc, > > > I got a 4.5 box which act as a perimeter ipsec routing gateway, > > > it has 682 flow (by ipsecctl -sf | wc

Re: Route modified dynamically

2010-03-11 Thread Paul de Weerd
On Fri, Mar 12, 2010 at 01:43:39AM +0100, Claudio Jeker wrote: | On Fri, Mar 12, 2010 at 12:28:33AM +, Stuart Henderson wrote: | > On 2010-03-10, Massimo Lusetti wrote: | > > Hi misc, | > > I got a 4.5 box which act as a perimeter ipsec routing gateway, it | > > has 682 flow (by ipsecctl -

Re: Route modified dynamically

2010-03-11 Thread Claudio Jeker
On Fri, Mar 12, 2010 at 12:28:33AM +, Stuart Henderson wrote: > On 2010-03-10, Massimo Lusetti wrote: > > Hi misc, > > I got a 4.5 box which act as a perimeter ipsec routing gateway, it > > has 682 flow (by ipsecctl -sf | wc -l). > > > > Some of this flow are up with a static route to the

Re: Route modified dynamically

2010-03-11 Thread Stuart Henderson
On 2010-03-10, Massimo Lusetti wrote: > Hi misc, > I got a 4.5 box which act as a perimeter ipsec routing gateway, it > has 682 flow (by ipsecctl -sf | wc -l). > > Some of this flow are up with a static route to the other point of the > ipsec tunnel and some of these routes are changing dynami

Re: Route modified dynamically

2010-03-10 Thread Massimo Lusetti
On Wed, 10 Mar 2010 09:44:36 +0100 Massimo Lusetti wrote: > Any hints is really appreciated. Should I stop accepting icmp redirect with the sysctl knobs as the changes in the 4.6 release? Cheers -- Massimo

Route modified dynamically

2010-03-10 Thread Massimo Lusetti
Hi misc, I got a 4.5 box which act as a perimeter ipsec routing gateway, it has 682 flow (by ipsecctl -sf | wc -l). Some of this flow are up with a static route to the other point of the ipsec tunnel and some of these routes are changing dynamically (netstat shows UGHMS flags). When these rou