Re: ipsec tunnel MTU issue [was: ipsec double lookup]

2006-03-31 Thread Herbert Xu
Marco Berizzi <[EMAIL PROTECTED]> wrote: > > Pleiadi is also running another tunnel with an old linux > 2.4.28/KLIPS FreeS/WAN 2.05 an the MTU is 1444. May anyone > explain me why ipsec tunnels established with linux 2.6.16 > (linux 2.6<->linux2.6) have an MTU equal to 1428? And why > tunnels esta

ipsec tunnel MTU issue [was: ipsec double lookup]

2006-03-31 Thread Marco Berizzi
Me again. I think I have found where the issue is. I have updated the network schema: customer private network 10.0.0.0/8 | | +ipsec customer gateway (nokia/checkpoint) |==MTU=1444 | | |---ipsec tunnel 10.0.0.0/8<->172.29.128.0/28 (3DES/MD5) | | |+---ipsec gateway (pleiadi)---priv net (172.16

ipsec double lookup

2006-03-30 Thread Marco Berizzi
Hello everybody. I have a problem with a sapgui<->sapserver connection after I have migrated an ipsec gateway, from linux 2.4.29/KLIPS FreeS/SWAN 2.05 to linux 2.6.16.1/NETKEY Openswan 2.4.5rc6 Here is my network schema (I hope it is clear): customer private network 10.0.0.0/8 | | +ipsec customer