Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 115813 - linux-2.6.14-gentoo-r2 / UDP/4500 encapsulated ipsec problem
Summary: linux-2.6.14-gentoo-r2 / UDP/4500 encapsulated ipsec problem
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Unspecified (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Kernel Bug Wranglers and Kernel Maintainers
Depends on:
Reported: 2005-12-16 15:06 UTC by Zoilo Gomez
Modified: 2006-01-25 05:46 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Zoilo Gomez 2005-12-16 15:06:12 UTC
Last week we did a fresh gentoo install, using stage3-x86-2005.1, portage-20051206 and ipsec-tools-0.6.3, ipv4, iptables-1.3.4, on a machine used as a router/gateway + VPN-client.

While using ipsec in tunnel mode with NAT-T (udp 4500), we use iptables POSTROUTING/SNAT for the gateway/router function on the same interface (eth0).

Strange behaviour: on linux-2.6.14-gentoo-r2 ipsec UDP/4500 packets are being sent out to a (seemingly) random UDP-port, instead of to UDP/4500. As a result a ping originating from this VPN-gateway through the tunnel cannot reach the VPN-server, as the UDP packets are not targeted to port 4500, but some weird port number (eg. 63542), disappearing into nowhere. In fact, each time I start a new ping, a different (random?) port number is used....(!).

However a ping from the VPN-gateway through the tunnel works fine! UDP-encapsulated packets travel between UDP/4500 <-> UDP/4500 as expected.

When the POSTROUTING rule is removed, the problem is disappears, however the NAT-gateway function is lost (obviously).

The problem was fixed by installing vanilla linux-2.4.13-3 kernel, with same .config (make oldconfig). I have other machines running on linux-2.6.12-10 as well with same configuration without problems.
Comment 1 Mike Doty (RETIRED) gentoo-dev 2005-12-16 15:13:12 UTC
not devrel related
Comment 2 Jeffrey Forman (RETIRED) gentoo-dev 2005-12-17 06:16:34 UTC
Quick change of platform in bugzilla. Sorry about the email.
Comment 3 Daniel Drake (RETIRED) gentoo-dev 2006-01-10 08:23:33 UTC
Is this reproducible on gentoo-sources-2.6.15?
Comment 4 Daniel Drake (RETIRED) gentoo-dev 2006-01-25 05:45:58 UTC
Please reopen when you respond to comment #3
Comment 5 Daniel Drake (RETIRED) gentoo-dev 2006-01-25 05:46:20 UTC
Sidenote: you should actually test the latest development kernel instead of 2.6.15. THis is currently 2.6.16-rc1