16
German - Deutsch / Re: Firewall Log Normal View
« on: May 10, 2018, 03:44:40 pm »
Schließe mich an, irgendeine Filtermöglichkeit wäre notwendig
Ld
Ld
This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.
In a packet capture, the actual address will be shown on outbound traffic, not the translated address. This does not indicate any problem.
14:31:26.676550 (authentic,confidential): SPI 0xbdb31e3b: IP 10.51.18.90 > 10.17.3.2: ICMP echo request, id 1, seq 873, length 40
14:31:26.712898 (authentic,confidential): SPI 0xcb1e1127: IP 10.17.3.2 > 192.168.16.90: ICMP echo reply, id 1, seq 873, length 40
pfctl -t bogonsv6 -T flush
rm /usr/local/etc/bogonsv6
/usr/local/etc/rc.update_bogons
charon {
..
ignore_acquire_ts=yes
..
}
If this is disabled the traffic selectors from the kernel's acquire events, which are derived from the triggering packet, are prepended to the traffic selectors from the configuration for IKEv2 connection. By enabling this, such specific traffic selectors will be ignored and only the ones in the config will be sent. This always happens for IKEv1 connections as the protocol only supports one set of traffic selectors per CHILD_SA.