<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: IPSEC VPN problems upgrading to Ubuntu Edgy</title>
	<atom:link href="http://johnleach.co.uk/words/243/ipsec-vpn-problems-upgrading-to-ubuntu-edgy/feed" rel="self" type="application/rss+xml" />
	<link>http://johnleach.co.uk/words/243/ipsec-vpn-problems-upgrading-to-ubuntu-edgy</link>
	<description>Stuff I think, see and do</description>
	<lastBuildDate>Mon, 14 May 2012 20:40:50 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
	<item>
		<title>By: Santhish</title>
		<link>http://johnleach.co.uk/words/243/ipsec-vpn-problems-upgrading-to-ubuntu-edgy/comment-page-1#comment-27833</link>
		<dc:creator>Santhish</dc:creator>
		<pubDate>Wed, 20 Feb 2008 15:03:09 +0000</pubDate>
		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2006/11/02/243/#comment-27833</guid>
		<description>Hi,

This is regarding the DNAT&#039;ing bug you&#039;ve been talking about.

I came across a similar issue  when IPSec and DNAT being used on the same peer. This applies only to kernel version below 2.6.16 and works well for kernel 2.6.18.

Observation:For example if I try to use Transparent Proxy using some DNAT..I find a new ESP packet originated from the translated IP(DNAT) towards the far end IPsec peer(Unintended behavior). 

This results in integrity check failure thus failed Transparent Proxy behavior.

Any comments,suggestions and workarounds are welcome.

Thanks,
Santhish.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>This is regarding the DNAT&#8217;ing bug you&#8217;ve been talking about.</p>
<p>I came across a similar issue  when IPSec and DNAT being used on the same peer. This applies only to kernel version below 2.6.16 and works well for kernel 2.6.18.</p>
<p>Observation:For example if I try to use Transparent Proxy using some DNAT..I find a new ESP packet originated from the translated IP(DNAT) towards the far end IPsec peer(Unintended behavior). </p>
<p>This results in integrity check failure thus failed Transparent Proxy behavior.</p>
<p>Any comments,suggestions and workarounds are welcome.</p>
<p>Thanks,<br />
Santhish.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Dynamic page generated in 0.071 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-05-23 04:39:22 -->

