<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: IPSEC VPN problems upgrading to Ubuntu Edgy</title>
	<atom:link href="http://johnleach.co.uk/words/archives/2006/11/02/243/ipsec-vpn-problems-upgrading-to-ubuntu-edgy/feed" rel="self" type="application/rss+xml" />
	<link>http://johnleach.co.uk/words/archives/2006/11/02/243/ipsec-vpn-problems-upgrading-to-ubuntu-edgy</link>
	<description>Stuff I think, see and do</description>
	<lastBuildDate>Sat, 24 Jul 2010 21:50:24 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Santhish</title>
		<link>http://johnleach.co.uk/words/archives/2006/11/02/243/ipsec-vpn-problems-upgrading-to-ubuntu-edgy/comment-page-1#comment-27833</link>
		<dc:creator>Santhish</dc:creator>
		<pubDate>Wed, 20 Feb 2008 15:03:09 +0000</pubDate>
		<guid isPermaLink="false">http://johnleach.co.uk/words/archives/2006/11/02/243/#comment-27833</guid>
		<description>Hi,

This is regarding the DNAT&#039;ing bug you&#039;ve been talking about.

I came across a similar issue  when IPSec and DNAT being used on the same peer. This applies only to kernel version below 2.6.16 and works well for kernel 2.6.18.

Observation:For example if I try to use Transparent Proxy using some DNAT..I find a new ESP packet originated from the translated IP(DNAT) towards the far end IPsec peer(Unintended behavior). 

This results in integrity check failure thus failed Transparent Proxy behavior.

Any comments,suggestions and workarounds are welcome.

Thanks,
Santhish.</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>This is regarding the DNAT&#8217;ing bug you&#8217;ve been talking about.</p>
<p>I came across a similar issue  when IPSec and DNAT being used on the same peer. This applies only to kernel version below 2.6.16 and works well for kernel 2.6.18.</p>
<p>Observation:For example if I try to use Transparent Proxy using some DNAT..I find a new ESP packet originated from the translated IP(DNAT) towards the far end IPsec peer(Unintended behavior). </p>
<p>This results in integrity check failure thus failed Transparent Proxy behavior.</p>
<p>Any comments,suggestions and workarounds are welcome.</p>
<p>Thanks,<br />
Santhish.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
