Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 08 Jan 2017 03:51:26 +0000
From:      bugzilla-noreply@freebsd.org
To:        freebsd-net@FreeBSD.org
Subject:   [Bug 213869] when setting an ipsec policy with spdadd src[port], outbound traffic from 2049/tcp is not encrypted
Message-ID:  <bug-213869-2472-wZfETw089J@https.bugs.freebsd.org/bugzilla/>
In-Reply-To: <bug-213869-2472@https.bugs.freebsd.org/bugzilla/>
References:  <bug-213869-2472@https.bugs.freebsd.org/bugzilla/>

next in thread | previous in thread | raw e-mail | index | archive | help
https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D213869

--- Comment #9 from Jason Mader <jasonmader@gmail.com> ---
Comment on attachment 178602
  --> https://bugs.freebsd.org/bugzilla/attachment.cgi?id=3D178602
Proposed patch (untested)

This worked for me.

root@safety:/usr/src/sys/netipsec # patch < ~/ipsec.c.diff
Hmm...  Looks like a unified diff to me...
The text leading up to this was:
--------------------------
|Index: sys/netipsec/ipsec.c
|=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
|--- sys/netipsec/ipsec.c       (revision 311647)
|+++ sys/netipsec/ipsec.c       (working copy)
--------------------------
Patching file ipsec.c using Plan A...
Hunk #1 succeeded at 241.
Hunk #2 succeeded at 344 (offset 1 line).
Hunk #3 succeeded at 501 (offset 1 line).
Hunk #4 succeeded at 511 (offset 1 line).
done

root@safety:~ # setkey -DP
fe80::%em0/64[any] fe80::a00:27ff:fefc:de09%em0[2049] tcp
        in ipsec
        esp/transport//require
        spid=3D1 seq=3D1 pid=3D806
        refcnt=3D1
fe80::a00:27ff:fefc:de09%em0[2049] fe80::%em0/64[any] tcp
        out ipsec
        esp/transport//require
        spid=3D2 seq=3D0 pid=3D806
        refcnt=3D1

I was able to NFSv4 mount a filesystem, and tcpdump is showing me that
everything is ESP.

--=20
You are receiving this mail because:
You are the assignee for the bug.=



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?bug-213869-2472-wZfETw089J>