Bug #6937

Inbound traffic on enc0 is not creating a state with mobile IPsec

Added by Jim Pingle 3 months ago. Updated 7 days ago.

Very High
Target version:
Start date:
Due date:
% Done:


Affected version:
Affected Architecture:


Traffic entering enc0 on 2.4 is not creating a state, thus TCP traffic will not pass. ICMP works as the return traffic will create a state outbound.


#1 Updated by Jim Pingle 3 months ago

  • Status changed from New to Confirmed

#2 Updated by Renato Botelho 3 months ago

  • Assignee set to Luiz Otavio O Souza

#3 Updated by Jim Pingle 3 months ago

  • Subject changed from Inbound traffic on enc0 is not creating a state to Inbound traffic on enc0 is not creating a state with mobile IPsec

After some more testing this appears to be a problem only with mobile IPsec, specifically (at least) IKEv2 EAP-RADIUS.

A site-to-site IPsec connection using IKEv1 or IKEv2 does not have the same problem, states are created properly.

A ping from a mobile IPsec client ( to the firewall LAN ( produces only this in the firewall states table:

enc0 icmp ->       0:0
   age 00:00:03, expires in 00:00:09, 3:0 pkts, 180:0 bytes, rule 88
   id: 00000000583e4bc5 creatorid: b95c5943

As you can see, that is in the "wrong" direction as it's the ICMP reply creating the state and not the original message from the client.

Attempting a TCP connection from the client to the server fails because TCP cannot create a state with a reply, instead, the dropped traffic shows in the firewall log:

Dec  1 12:46:32 block enc0 TCP:SA

Dec  1 12:47:02 shona filterlog: 6,16777216,,1000000104,enc0,match,block,out,4,0x0,,64,0,0,DF,6,tcp,48,,,443,50132,0,SA,1687100934,2626059616,65228,,mss;sackOK;eol

#4 Updated by Jun Wang about 1 month ago

Found the same problem on a 2 weeks old SG-1000. Kinda annoying since mobile ipsec is the reason I bought it.

#6 Updated by Luiz Otavio O Souza 14 days ago

  • Status changed from Confirmed to Feedback

#7 Updated by Jim Pingle 14 days ago

No change on the latest snap built after that commit.

#8 Updated by Jim Pingle 7 days ago

  • Status changed from Feedback to Assigned

Also available in: Atom PDF