Project

General

Profile

Actions

Bug #1841

closed

TCP state issue when traffic passing through a GRE tunnel within IPSEC

Added by Nigel Wright over 12 years ago. Updated over 8 years ago.

Status:
Duplicate
Priority:
Normal
Assignee:
-
Category:
Interfaces
Target version:
-
Start date:
09/06/2011
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
Affected Architecture:

Description

When running a GRE tunnel between two Pfsense 2.0 RC3 TCP traffic is shown as having its SYN/ACK packets dropped on the returning firewall.
This has been established in two scenarios.

Scenario 1 GRE tunnel between WAN interfaces, IPSEC in transport mode between the two WAN interfaces. Ping works fine TCP sessions have SYN/ACK packets dropped on the returning firewall. When IPSEC is disabled everything works fine.

Scenario 2 IPSEC tunnel between LAN interface addresses, GRE tunnel bound to LAN interface. Ping works fine TCP SYN/ACK packets dropped on return.


Files

Pfsense_GRE.zip (121 KB) Pfsense_GRE.zip Nigel Wright, 02/27/2012 05:10 PM
Actions

Also available in: Atom PDF