[Openswan Users] Packet has no Non-ESP marker
paul at xelerance.com
Mon Nov 13 15:11:18 EST 2006
On Mon, 13 Nov 2006, Stefan Denker wrote:
> Nov 13 11:11:25 seikan pluto: packet from 188.8.131.52:4500: recvfrom 184.108.40.206:4500 has no Non-ESP marker
> Nov 13 11:11:56 seikan last message repeated 7 times
> What is this "Non-ESP marker"?
When IKE packets arrive on port-4500, they are ESP-UDP encapsulated.
This means that they really have an ESP header after ther UDP packet.
If the SPI# of the ESP header is 0, then it's an IKE packet.
That's the "non-ESP marker"
Perhaps you are DNAT'ing IKE packets?
Building and integrating Virtual Private Networks with Openswan:
More information about the Users