Cannot add XFRM or VTI Interfaces

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Goto page Previous  1, 2
Author Message
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14224
Location: Texas, USA

PostPosted: Thu Jun 25, 2020 20:22    Post subject: Reply with quote
I linked a thread and told you who to ask directly earlier in this thread.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
Sponsor
tkmds
DD-WRT User


Joined: 04 Sep 2011
Posts: 161
Location: SA

PostPosted: Thu Jun 25, 2020 21:37    Post subject: Reply with quote
So I did read that thread link.

As for the contacts, usually, I'll interpret that to mean an invitation to join current thread.

My bad. I'll ask them on that thread.

Wink

_________________
Cheers, TK
------------------------
tkmds
DD-WRT User


Joined: 04 Sep 2011
Posts: 161
Location: SA

PostPosted: Mon Jun 29, 2020 17:57    Post subject: Reply with quote
Just to recap, trying to get my StrongSwan / IPSec DD-WRT working with Azure VPN Gateways. Here's what I see.

I've ran tcpdump against the WAN vlan2 interface and ipsec0 interface to see where the traffic stops while trying to ping the remove Azure VM behind the Azure Gateway.

Azure VPN Gateway -> DD-WRT StrongSwan (WORKING):
Code:
I see traffic on both the vlan2 and ipsec0 interface.


DD-WRT StrongSwan / IPSEC -> Azure VPN Gateway (NON-WORKING):
Code:
I only see traffic on ipsec0 and nothing get's passed to vlan2.


I've been trying to see about compiling and adding in some missing StrongSwan / IPSec modules into my router but I'm not 100% convinced, yet, that could be the issue.


So my question is, why doesn't StrongSwan / IPSec not pass traffic from ipsec0 to vlan2 but does the other way? What am I missing?

I'm thinking I'm missing a F/W rule perhaps to get this to work but not 100%. Tried a few but none have worked.

Other then that, I would be curious what did Kong add to his builds to get IPSec to work? I'd be curious to see those notes to then determine what I'm missing.

_________________
Cheers, TK
------------------------
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14224
Location: Texas, USA

PostPosted: Mon Jun 29, 2020 18:52    Post subject: Reply with quote
I am not sure anyone has direct contact with <Kong> these days, and this touches on a very sore subject. Whether or not he even retained a backup of his working copy DD-WRT code repository is not known, but as far as I know, he obliterated it and replaced it with OpenWRT. I do not know if @egc or any of the other folks may have made any progress with this or not. All I know is some features and kernel modules may or may not be included in public releases due to firmware image size constraints.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
tkmds
DD-WRT User


Joined: 04 Sep 2011
Posts: 161
Location: SA

PostPosted: Mon Jun 29, 2020 19:32    Post subject: Reply with quote
Allright.

If @egc could dig up the two dependent modules from that earlier build, I could test out with xfrm_user and see if these dependent modules finally allow connectivity.

I've asked on that thread earlier. I'll wait for his reply. Chances are he has them if he was able to provide the earlier zip file.

In the meantime, I'll try to finish compiling the firmware kernel. If that works, I should be able to generate the modules myself or exclude / include any other features to get this to work.

_________________
Cheers, TK
------------------------
Goto page Previous  1, 2 Display posts from previous:    Page 2 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum