IP forwarding on a linux IPSec gateway

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Hi,

I am trying to establish an IPSec tunnel to protect a subnet behind a linux machine and a subnet behind some other gateway.
Lefsubnet - 172.17.0.0/16 (behind linux gateway)
Rightsubnet - 172.16.0.0/16

>From a host on left subnet, I am trying to ping to a host on right subnet-
ping 172.16.60.1 -I 172.17.70.87

tcpdump capture on linux machine connected to left subnet-
04:27:09.939598 IP 172.17.70.87 > 172.16.60.1: icmp 64: echo request seq 170

Tcpdump capture on linux machine connected on right subnet-
04:26:32.941624 IP 1.1.0.1 > 192.168.101.101: ESP(spi=0x020000c3,seq=0x16d)                 //Outer IPs
04:26:32.943940 IP 192.168.101.101 > 1.1.0.1: ESP(spi=0x10000102,seq=0x16d)
04:26:32.943940 IP 172.16.60.1 > 172.17.70.87: icmp 64: echo reply seq 133

So, it's clear that linux gateway is able to protect the data and send to the connected gateway (ESP packets to outer IPs).
And the second gateway is responding with ESP packet which is decoded on linux gateway and sent to the ip stack again by linux kernel (ICMP reply).
But the reply doesn't reach the host on left subnet.

I enabled ip_forwarding through /proc/sys/net/ipv4/ip_forwarding.

Please let me know, if I am missing something.

Any help would be appreciated.

Regards,
Prashant

--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Linux Kernel Discussion]     [Ethernet Bridging]     [Linux Wireless Networking]     [Linux Bluetooth Networking]     [Linux Networking Users]     [VLAN]     [Git]     [IETF Annouce]     [Linux Assembly]     [Security]     [Bugtraq]     [Photo]     [Singles Social Networking]     [Yosemite Information]     [MIPS Linux]     [ARM Linux Kernel]     [ARM Linux]     [Linux Virtualization]     [Linux Security]     [Linux IDE]     [Linux RAID]     [Linux SCSI]     [Free Dating]

Add to Google Powered by Linux