New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
IPsec Tunnel Deterministic Delay #156
Comments
On Wed, 25 Nov 2015, japita-se wrote:
Looks like there was fragmentation at the UDP layer there? Perhaps the
libreswan supports IKEv1 and IKEv2 fragmentation so UDP packets won't Paul |
I admit my ignorance of libreswan details. I do not know if it is a fragmentation problem. In other forums where people paste their packet dumps the I saw the same issue (exactly 15 secs of delay between the conclusion of phase 2 even if the packets arrive immediately). How can I debug? |
plutodebug=all Sent from my iPhone
|
It was already set. I see a lot of "unpadded size is: 56 _received 84 bytes from remore-ip:500 on eth1 (port=500) |
On Thu, 26 Nov 2015, japita-se wrote:
It was already set. I see a lot of "unpadded size is: 56
An excerpt of /var/log/plugo.log:
you need to know the log of what happens in/around the 15 seconds.
libreswan has an option logtime=yes that will also log timestamps.
Paul
|
0
down vote
favorite
I setup a site-to-site IPSec tunnel using OpensWan.
I noticed that there is always a delay of 15 sec betwenn the phase 1 and phase 2 as shown in this tcpdump. Does anybody know why?
17:50:41.638828 IP remotepeer.40237 > miyazaki.47087: Flags [S.], seq 539598201, ack 3547092391, win 5792, options [mss 1380,sackOK,TS val 1866473592 ecr 1322888897,nop,wscale 3], length 0 17:50:41.695067 IP remotepeer.40237 > miyazaki.47087: Flags [.], ack 593, win 872, options [nop,nop,TS val 1866473647 ecr 1322888954], length 0 17:50:41.897514 IP remotepeer.40237 > miyazaki.47087: Flags [P.], seq 1:161, ack 593, win 872, options [nop,nop,TS val 1866473850 ecr 1322888954], length 160 17:50:41.952144 IP remotepeer.40237 > miyazaki.47087: Flags [P.], seq 161:426, ack 593, win 872, options [nop,nop,TS val 1866473905 ecr 1322889212], length 265 17:50:56.897125 IP remotepeer.40237 > miyazaki.47087: Flags [F.], seq 426, ack 593, win 872, options [nop,nop,TS val 1866488851 ecr 1322889267], length 0 17:50:56.952014 IP remotepeer.40237 > miyazaki.47087: Flags [.], ack 594, win 872, options [nop,nop,TS val 1866488906 ecr 1322904212], length 0
The text was updated successfully, but these errors were encountered: