2006-04-16

transport mode IPsec AH, ESP and IPcomp

I tested this until I got smaller packets (!500bytes) in both directions with 5000 byte pings. This uses a fairly default racoon configuration. (I used pre-shared key)

node A

spdadd B A any -P in ipsec
ah/transport//require
esp/transport//require
ipcomp/transport//require;

spdadd A B any -P out ipsec
ipcomp/transport//require
esp/transport//require
ah/transport//require;

node B

spdadd A B any -P in ipsec
ah/transport//require
esp/transport//require
ipcomp/transport//require;

spdadd B A any -P out ipsec
ipcomp/transport//require
esp/transport//require
ah/transport//require;

Blog/2006-04-16 (last edited 2006-04-16 22:13:49 by JonathanKollasch)