RE: port bound SAs

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Paul Moore
Date: Tuesday, January 27, 2009 - 9:53 am

my inspection of the code shows that the port numbers in the SA do not
get propagated into the right places
in transport mode linux is never aware of the port numbers 
racoon systematically zeros them out during SA setup, but even if i
correct the racoon code to put the port number in it still fails becuase
the port numbers get ignored by the kernel

-----Original Message-----
From: David Miller [mailto:davem@davemloft.net] 
Sent: Monday, January 26, 2009 10:21 PM
To: Paul Moore
Cc: netdev@vger.kernel.org
Subject: Re: port bound SAs

From: "Paul Moore" <paul.moore@centrify.com>
Date: Mon, 26 Jan 2009 11:21:33 -0800

peer
it

Why does the Linux system do this?  The route lookup should, as it's
final IPSEC route lookup action, do an xfrm policy lookup which should
do a selector match and thus not match the port 23 rule.

I can't find the code which would allow the sequence of events
you describe, can you?
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
port bound SAs, Paul Moore, (Mon Jan 26, 12:21 pm)
Re: port bound SAs, David Miller, (Mon Jan 26, 11:20 pm)
Re: port bound SAs, Patrick McHardy, (Tue Jan 27, 3:26 am)
RE: port bound SAs, Paul Moore, (Tue Jan 27, 9:46 am)
RE: port bound SAs, Paul Moore, (Tue Jan 27, 9:53 am)
Re: port bound SAs, Patrick McHardy, (Tue Jan 27, 10:01 am)
RE: port bound SAs, Paul Moore, (Tue Jan 27, 10:05 am)
Re: port bound SAs, Patrick McHardy, (Tue Jan 27, 10:12 am)
RE: port bound SAs, Paul Moore, (Tue Jan 27, 10:13 am)
Re: port bound SAs, David Miller, (Tue Jan 27, 10:21 am)
Re: port bound SAs, Patrick McHardy, (Tue Jan 27, 10:21 am)
RE: port bound SAs, Paul Moore, (Tue Jan 27, 10:21 am)
RE: port bound SAs, Paul Moore, (Tue Jan 27, 10:24 am)
Re: port bound SAs, Patrick McHardy, (Tue Jan 27, 10:29 am)
RE: port bound SAs, Paul Moore, (Tue Jan 27, 10:38 am)
Re: port bound SAs, Patrick McHardy, (Tue Jan 27, 10:42 am)
RE: port bound SAs, Paul Moore, (Wed Jan 28, 10:17 am)
Re: port bound SAs, Patrick McHardy, (Wed Jan 28, 11:03 am)
RE: port bound SAs, Paul Moore, (Wed Jan 28, 11:07 am)
Re: port bound SAs, Patrick McHardy, (Wed Jan 28, 11:11 am)
RE: port bound SAs, Paul Moore, (Wed Jan 28, 11:27 am)
RE: port bound SAs, Paul Moore, (Thu Jan 29, 10:23 am)
Re: port bound SAs, Herbert Xu, (Thu Jan 29, 11:30 pm)
xfrm selector generating IKE, Paul Moore, (Mon Feb 23, 6:31 pm)
Re: xfrm selector generating IKE, Herbert Xu, (Mon Feb 23, 7:08 pm)
RE: xfrm selector generating IKE, Paul Moore, (Tue Feb 24, 10:23 am)
Re: xfrm selector generating IKE, Herbert Xu, (Tue Feb 24, 5:33 pm)
RE: xfrm selector generating IKE, Paul Moore, (Tue Feb 24, 7:07 pm)
Re: xfrm selector generating IKE, Herbert Xu, (Tue Feb 24, 7:27 pm)
RE: xfrm selector generating IKE, Paul Moore, (Tue Feb 24, 7:30 pm)
Re: xfrm selector generating IKE, Herbert Xu, (Tue Feb 24, 7:38 pm)