|
|||||||||||
|
Re: linux-ipsec: Latest IPsec and connecting two IP networks.... :-(
From: David Sainty <DavidSainty(at)cit.com.au>
Date: Wed Sep 02 1998 - 18:33:35 EDT I have a new thought on this. While these problems were occurring here on "machine1", the IPsec configuration on the other Linux machine / firewall, "machine2" was still basically configured (and at one stage partially but incorrectly configured). Is it possible that: 1/ An IPsec machine (machine2) could send packets to a machine with an IPsec'd kernel but not the correct IPsec configuration (machine1) or 2/ An IPsec machine with a "damaged" IPsec configuration (machine2) could send packets to a good machine (machine1) and cause machine1's networking code to get so confused that the _networking on that physical external interface_ dies?? You see, after my problems (below) yesterday I only realised last night that the IPsec configuration on machine2 (which is in another state and only controlled by me via ssh) had been messed up all day (somehow it was missing its IP4 spi entry but it still had its two ESP entries)..... I fixed this problem while the local firewall was up ( ;-) ) and since then I don't appear to have had problems............... Here's something to chew on. :-) David S..
David Sainty wrote:
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:26 EDT |
||||||||||
|
|||||||||||