OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
IPsec trouble in 3.3-current + 3.3-stable bind

From: Alexey E. Suslikov (crueltexnika.com.ua)
Date: Thu Jul 24 2003 - 01:26:50 CDT


3.3-current from 20030716 on ext.src.src.src
3.3-stable from 20030605 on ext.dst.dst.dst

i have tried make this bind working, but got the following:

- icmp

Jul 24 08:47:37.450067 (authentic,confidential): SPI 0x990ac7f5:
ext.src.src.src > ext.dst.dst.dst: enc.src.src.src > enc.dst.dst.dst:
icmp: echo request (id:3733 seq:16128) (ttl 255, id 42388) (ttl 64, id 49933, bad cksum 0!)

Jul 24 08:47:37.491939 (authentic,confidential): SPI 0xd066cc03: truncated-ip - 48 bytes missing!
ext.dst.dst.dst > ext.src.src.src: enc.dst.dst.dst > enc.src.src.src:
icmp: echo reply (id:3733 seq:16128) (ttl 255, id 22151) (ttl 64, id 15205)

- tcp

Jul 24 08:47:29.269261 (authentic,confidential): SPI 0x8a42893d: truncated-ip - 52 bytes missing!
ext.dst.dst.dst > ext.src.src.src: enc.dst.dst.dst.23062 > enc.src.src.src.3128:
S [tcp sum ok] 2505265291:25052652 91(0) win 16384 <mss 1240,nop,nop,sackOK,nop,wscale 0,nop,
nop,timestamp 410811190 0> (DF) (ttl 64, id 54630) (DF) (ttl 64, id 36157)

any ideas?