1 msgRe: New gaim packages fix denial of service
1 msgtuning the samba log file
1 msgPhilippe CAILLEAUD/SIEGE/MAIF est absent.

IPsec from native KAME in 2.6 kernel to FreeS/W...
\ Igor Goldenberg (27 Jul 2005)

11 msgSecurity fixes for mozilla and firefox in Sarge?
3 msgRe: [SECURITY] [DSA 765-1] New heimdal packages...
4 msgPlease announce current lack of security support
2 msgRe: Bug#319406: heartbeat: upgrade and reconfig...
2 msgLinking monotone with the official lua shared l...
1 msga compromised maschine
19 msga compromised machine
1 msgÃÈÁÄÄÏðîâîäêè-ÖÁÍîâèíêè-áàç-äàííûõÂÝÄ
1 msgRe: CD 2004
5 msglast -t lists all entries in wtmp
18 msgHelp needed - server hacked twice in three days...
1 msge-mail address change for Barrie Webster
2 msgfreeRadius 1.0.4
3 msgIDS detected smbpasswd modified
2 msgRe: [MIB-Admin] [SECURITY] [DSA 757-1] New krb5...
1 msgRe: New krb5 packages fix multiple vulnerabilities
Subject:IPsec from native KAME in 2.6 kernel to FreeS/WAN on 2.4
Group:Debian-security
From:Igor Goldenberg
Date:27 Jul 2005


 
Hello.

I have the central security gateway ("server") with FreeS/WAN v2.06 and
a number of client security gateways with the same FreeS/WAN on its.
Between the server and client gateways exists more then one tunnel
having the same endpoints. For example, for scheme

net1/24 == gw1 ... gw2 == (serv1 & serv2)

I've 2 tunnels: net1/24 <-> serv1 and net1/24 <-> serv2, both having the
same endpoints: gw1 and gw2.

When FreeS/WAN start these connections it create a "IPsec SA" *for*
*each* and work then with its. I think it's implementation feature.

But native 2.6 IPsec use one common "IPsec SA" for each tunnel sharing
common endpoint IPs and policies. And when I use on client gateway linux
2.6 with ëáíå, only first IPsec connection work as expected. Racoon and
Pluto setup "IPsec SA" for this tunnel. But when some trafic from
net1/24 want to go to serv2, kernel on client gateway try to use
existing SA but FreeS/WAN don't have "IPsec SA" established for *this*
connection and trafic can't go.

Is it possible to inform FreeS/WAN use existing "IPsec SA" for others
connection through the same gateway? Or there are other soulutions exist?

--
Igor.


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com