IPSec Fallback mechanism subnet/supernet

IPSec Fallback mechanism subnet/supernet

NewsGroups | Search | Tools
 comp.dcom.vpn  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
IPSec Fallback mechanism subnet/supernet anshul makkar 01-08-2008
Posted by anshul makkar on January 8, 2008, 11:17 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

I established two IPSEC tunnels terminating at one hub.
Configuration :
1st tunnel : right subnet as 192.168.4.0/24
2nd tunnel: right subnet as 192.168.0.0/16

Both the tunnels have same gateway as 172.16.28.108

I am using freeswan code.

Now what I am observing is that, if I disable the 192.168.4.0/24
tunnel, and send ping request to 192.168.4.1, the ICMP IPSEC SA is
negotiated for 2nd tunnel (supernet one which is already correctly
established.). Why this is happening.

Further, on continuous pinging (to machine on network 192.168.4.0/24),
a new IPSEC SA (for tunnel 192.168.0.0/26) is negotiated on every
request.

On debugging I found that when I disable a perticular tunnel, the path
corresponding to it is marked as trapped. Now klips capture the
outbound packets on the trapped path and tries to send it through
another closest matched active path. Thus in this scenrio, klips is
capturing the outbound packets destined for 192.168.4.0/24 subnet and
is trying to transfer it through 192.168.0.0/16. Is my inference
correct.

If this is the default behavior, then why IPSEC SA is being
renegotiated for every outbound ICMP packet. (IPSEC SA should be
established once and then used for every evey ping request)

Please if you have any hint or refernce then please do share it .

Thanking You
Anshul Makkar

Network Magic 20% Off NMEASY coupon code spring banner 468x60
Posted by anshul makkar on January 14, 2008, 12:44 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

Please reply.
Thanks

> Hi,
>
> I established =A0two IPSEC tunnels terminating at one hub.
> Configuration :
> 1st tunnel : right subnet as 192.168.4.0/24
> 2nd tunnel: right subnet as 192.168.0.0/16
>
> Both the tunnels have same gateway as 172.16.28.108
>
> I am using freeswan code.
>
> Now what I am observing is that, if I disable the 192.168.4.0/24
> tunnel, and send ping request to 192.168.4.1, the ICMP IPSEC SA is
> negotiated for 2nd tunnel (supernet one which is already correctly
> established.). Why this is happening.
>
> Further, on continuous pinging (to machine on network 192.168.4.0/24),
> a new IPSEC SA (for tunnel 192.168.0.0/26) is negotiated on every
> request.
>
> On debugging I found that when I disable a perticular tunnel, the path
> corresponding to it is marked as trapped. Now klips capture the
> outbound packets on the trapped path and tries to send it through
> another closest matched active path. Thus in this scenrio, klips is
> capturing the outbound packets destined for 192.168.4.0/24 subnet and
> is trying to transfer it through 192.168.0.0/16. Is my inference
> correct.
>
> If this is the default behavior, then why IPSEC SA is being
> renegotiated for every outbound ICMP packet. (IPSEC SA should be
> established once and then used for every evey ping request)
>
> Please if you have any hint or refernce then please do share it .
>
> Thanking You
> Anshul Makkar


Posted by . on February 22, 2008, 3:58 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> Hi,
>
> Please reply.
> Thanks
>
>
> > Hi,
>
> > I established two IPSEC tunnels terminating at one hub.
> > Configuration :
> > 1st tunnel : right subnet as 192.168.4.0/24
> > 2nd tunnel: right subnet as 192.168.0.0/16
>
> > Both the tunnels have same gateway as 172.16.28.108
>
> > I am using freeswan code.
>
> > Now what I am observing is that, if I disable the 192.168.4.0/24
> > tunnel, and send ping request to 192.168.4.1, the ICMP IPSEC SA is
> > negotiated for 2nd tunnel (supernet one which is already correctly
> > established.). Why this is happening.
>
> > Further, on continuous pinging (to machine on network 192.168.4.0/24),
> > a new IPSEC SA (for tunnel 192.168.0.0/26) is negotiated on every
> > request.
>
> > On debugging I found that when I disable a perticular tunnel, the path
> > corresponding to it is marked as trapped. Now klips capture the
> > outbound packets on the trapped path and tries to send it through
> > another closest matched active path. Thus in this scenrio, klips is
> > capturing the outbound packets destined for 192.168.4.0/24 subnet and
> > is trying to transfer it through 192.168.0.0/16. Is my inference
> > correct.
>
> > If this is the default behavior, then why IPSEC SA is being
> > renegotiated for every outbound ICMP packet. (IPSEC SA should be
> > established once and then used for every evey ping request)
>
> > Please if you have any hint or refernce then please do share it .
>
> > Thanking You
> > Anshul Makkar

Hi
IPSec tuto:
http://secure-vpn.com/PPTP-L2TP.rar

Similar ThreadsPosted
IKE and IPSEC October 10, 2007, 8:54 am
Need help routing IPX over IPsec February 10, 2005, 11:35 pm
GRE traffic over PIX IPSEC VPN June 6, 2005, 5:55 pm
trouble connecting XP over IPSec VPN March 4, 2005, 5:37 pm
IPSec over L2TP - Snapgear + NAT December 2, 2005, 3:07 am
Bintec VPN 25 - Zyxel VPN IPSec December 2, 2005, 4:30 am
IPSEC VPN using Belgian EID Card ? March 21, 2006, 9:06 am
Access to IPSec VPN through Netscreen-10 fw March 28, 2006, 2:38 pm
Questions about IPSec Identifier January 16, 2007, 2:55 pm
vpn 3000 to checkpoint ipsec May 28, 2007, 6:06 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map