Re: DNS over IPSec weirdness

2014-12-17 Thread Zé Loff
On Thu, Dec 11, 2014 at 04:13:13PM +, Zé Loff wrote: > TL,DR: > Queries to DNS server over IPSec made using host or dig work OK, > requests made by e.g. ping exit the enc0 interface but don't show up on > enc0 on the other end. > > > Hi all > > I'm puzzled by some weird stuff happening with

Re: DNS over IPSec weirdness

2014-12-12 Thread David Dahlberg
First of all, I have no real clue. It sound weird. But maybe I can help you at least with that one: Am Donnerstag, den 11.12.2014, 16:13 + schrieb Zé Loff: > However, if I try to do something like "ping -c 1 www_lan.foo.bar" (or > e.g. ssh) I can see the packets with the DNS request pass throu

Re: DNS over IPSec weirdness

2014-12-11 Thread R0me0 ***
Hey man, I'm not sure about what is happening, but pflog is your best friend ever ! http://www.openbsd.org/faq/pf/logging.html Try find out if a specific rule is blocking traffic in one of endpoints ( both ? ) Cheers, 2014-12-11 14:13 GMT-02:00 Zé Loff : > TL,DR: > Queries to DNS server over

DNS over IPSec weirdness

2014-12-11 Thread Zé Loff
TL,DR: Queries to DNS server over IPSec made using host or dig work OK, requests made by e.g. ping exit the enc0 interface but don't show up on enc0 on the other end. Hi all I'm puzzled by some weird stuff happening with DNS queries over IPSec. I have a fully working tunnel over a roaming laptop