[Openswan Users] OpenSwan and locally-generated traffic

Paul Wouters paul at xelerance.com
Wed Nov 5 22:15:06 EST 2008


On Wed, 5 Nov 2008, James Northcott / Chief Systems wrote:

> I'm having trouble getting locally-generated traffic to pass through the
> IPSEC tunnel.

Add the appropriate leftsourceip= and rightsourceip= options to the conn.

> I'm not sure why the first tcpdump command doesn't show packets from 0.10
> to 3.102, but things work when this is the case.

Linux kernel design issue with NETKEY.

> The netkey stuff seems very opaque to me, I'm not sure where to look to
> see what is happening to the disappearing packets.  They do not appear in

> I'd appreciate some pointers on where to look to investigate further.

you might be able to see a little bit more using:

ifconfig eth0:bogus 1.2.3.4
tcpdump -i eth0:bogus

Linux secret sauces.....

Paul


More information about the Users mailing list