Received: with ECARTIS (v1.0.0; list netdev); Thu, 21 Apr 2005 17:58:18 -0700 (PDT) Received: from arnor.apana.org.au (arnor.apana.org.au [203.14.152.115]) by oss.sgi.com (8.12.10/8.12.10/SuSE Linux 0.7) with ESMTP id j3M0w8dD010839 for ; Thu, 21 Apr 2005 17:58:13 -0700 Received: from gondolin.me.apana.org.au ([192.168.0.6] ident=mail) by arnor.apana.org.au with esmtp (Exim 3.35 #1 (Debian)) id 1DOmRY-0003vU-00; Fri, 22 Apr 2005 10:54:52 +1000 Received: from herbert by gondolin.me.apana.org.au with local (Exim 3.36 #1 (Debian)) id 1DOmRU-0002p4-00; Fri, 22 Apr 2005 10:54:48 +1000 Date: Fri, 22 Apr 2005 10:54:48 +1000 To: jamal Cc: Wolfgang Walter , netdev@oss.sgi.com Subject: Re: Problem with IPSEC tunnel mode Message-ID: <20050422005448.GA10819@gondor.apana.org.au> References: <200504211640.16742.wolfgang.walter@studentenwerk.mhn.de> <20050421214618.GA29991@gondor.apana.org.au> <1114127419.10572.4.camel@localhost.localdomain> <20050421235802.GB10451@gondor.apana.org.au> <1114129099.10572.24.camel@localhost.localdomain> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1114129099.10572.24.camel@localhost.localdomain> User-Agent: Mutt/1.5.6+20040907i From: Herbert Xu X-Virus-Scanned: ClamAV 0.83/848/Thu Apr 21 12:37:33 2005 on oss.sgi.com X-Virus-Status: Clean X-archive-position: 252 X-ecartis-version: Ecartis v1.0.0 Sender: netdev-bounce@oss.sgi.com Errors-to: netdev-bounce@oss.sgi.com X-original-sender: herbert@gondor.apana.org.au Precedence: bulk X-list: netdev Content-Length: 682 Lines: 18 On Thu, Apr 21, 2005 at 08:18:19PM -0400, jamal wrote: > > So i was wondering whether they OUT shouldnt be just a duplicate of > FWD (instead FWD seems to be the dup of IN). Look at that sample i > posted - all his policies look like that. What gives? Why are the IN and > FWD exactly the same? bug in racoon/setkey? FWD checks inbound IPsec policies while OUT determines the outbound IPsec policies. The IN direction is not used at all for forwarded packets. Cheers, -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt