<div id="mb_0">
<div>All--</div>
<div> </div>
<div>I have a curious problem I was hoping somebody could help me out with.</div>
<div> </div>
<div>I've got a Linux 2.4.21 (klips) client trying to connect to a Linux 2.6.20 (netkey) IPSec gateway. Both are using Openswan 2.4.7.</div>
<div> </div>
<div>Everything works fine to a point; the SA is successfully establishes but my routing seems to be somehow busted and I'm just not getting my noodle around it. I can ping from one side to the other (tcpdump show the incoming ESP) but I never get any ICMP replies back in either direction. There's nothing to speak of errorwise.
</div>
<div> </div>
<div>HostA starts the connection from with it's NATed environment to HostB who adds the connection. Here's the topology and conn:</div>
<div> </div>
<div>HostA <----> NAT <---- internet ----> HostB</div>
<div> </div>
<div>conn HostA-HostB</div>
<div> left=HostBpublicIP</div>
<div> leftnexthop=HostBPublicDefaultGW</div>
<div> leftsubnet=HostB/32</div>
<div> leftid=...</div>
<div> leftca=...</div>
<div> leftcert=...</div>
<div> leftrsasigkey=%cert</div>
<div> right=HostAPrivateIP</div>
<div> rightid=HostAPublicIP</div>
<div> rightnexthop=HostAPrivateDefaultGW</div>
<div> rightca=...</div>
<div> rightcert=%cert</div>
<div> rightrsasigkey=...</div>
<div> rightsubnet=HostA/32</div>
<div> </div>
<div>The curious thing is that I can see the ike traffic going back and forth but ESP only goes one way. Any thoughts or pointers?</div>
<div> </div>
<div>Thanks!</div><span class="sg">
<div> </div>
<div>Ben--</div></span></div>