Use transport mode ESP SA if IPcomp is used, IPcomp already applies outer IP header

This commit is contained in:
Martin Willi
2009-11-26 16:03:06 +01:00
parent 52fd0ef9e0
commit 2b2c69e992
2 changed files with 16 additions and 4 deletions
+4
View File
@@ -13,6 +13,10 @@ strongswan-4.3.6
bit truncation used by previous releases. To use the old 96 bit truncation bit truncation used by previous releases. To use the old 96 bit truncation
scheme, the new "sha256_96" proposal keyword has been introduced. scheme, the new "sha256_96" proposal keyword has been introduced.
- Fixed IPComp in tunnel mode, stripping out the duplicated outer header. This
change makes IPcomp tunnel mode connections incompatible with previous
releases; disable compression on such tunnels.
strongswan-4.3.5 strongswan-4.3.5
---------------- ----------------
@@ -946,6 +946,8 @@ static status_t add_sa(private_kernel_netlink_ipsec_t *this,
ENCR_UNDEFINED, chunk_empty, AUTH_UNDEFINED, chunk_empty, ENCR_UNDEFINED, chunk_empty, AUTH_UNDEFINED, chunk_empty,
mode, ipcomp, 0, FALSE, inbound); mode, ipcomp, 0, FALSE, inbound);
ipcomp = IPCOMP_NONE; ipcomp = IPCOMP_NONE;
/* use transport mode ESP SA, IPComp uses tunnel mode */
mode = MODE_TRANSPORT;
} }
memset(&request, 0, sizeof(request)); memset(&request, 0, sizeof(request));
@@ -1663,6 +1665,15 @@ static status_t add_policy(private_kernel_netlink_ipsec_t *this,
} }
tmpl++; tmpl++;
/* use transport mode for ESP if we have a tunnel mode IPcomp SA */
mode = MODE_TRANSPORT;
}
else
{
/* when using IPcomp, only the IPcomp SA uses tmp src/dst addresses */
host2xfrm(src, &tmpl->saddr);
host2xfrm(dst, &tmpl->id.daddr);
} }
tmpl->reqid = reqid; tmpl->reqid = reqid;
@@ -1671,9 +1682,6 @@ static status_t add_policy(private_kernel_netlink_ipsec_t *this,
tmpl->mode = mode2kernel(mode); tmpl->mode = mode2kernel(mode);
tmpl->family = src->get_family(src); tmpl->family = src->get_family(src);
host2xfrm(src, &tmpl->saddr);
host2xfrm(dst, &tmpl->id.daddr);
if (this->socket_xfrm->send_ack(this->socket_xfrm, hdr) != SUCCESS) if (this->socket_xfrm->send_ack(this->socket_xfrm, hdr) != SUCCESS)
{ {
DBG1(DBG_KNL, "unable to add policy %R === %R %N", src_ts, dst_ts, DBG1(DBG_KNL, "unable to add policy %R === %R %N", src_ts, dst_ts,