> А можете ещё сделать bpf_mask=3 для входящих пакетов? Для каждого
> входящего пакета тогда будет по две записи.
Сделал.
# sysctl net.enc.in.ipsec_bpf_mask=3
net.enc.in.ipsec_bpf_mask: 1 -> 3
Картина не поменялась, в смысле ответов так и нет.
# ipsec status
Routed Connections:
10.7.0.12{1}: ROUTED, TUNNEL, reqid 1
10.7.0.12{1}:
192.168.58.0/24 ===
192.168.44.0/24
Security Associations (1 up, 0 connecting):
10.7.0.12[1]: ESTABLISHED 24 minutes ago,
10.7.0.41[10.7.0.41]...10.7.0.12[10.7.0.12]
10.7.0.12{2}: INSTALLED, TUNNEL, reqid 1, ESP SPIs: c2e51929_i
c355fdbf_o
10.7.0.12{2}:
192.168.58.0/24 ===
192.168.44.0/24
Дамп:
12:01:27.221212 (authentic,confidential): SPI 0xc2e51929: IP 10.7.0.12 >
10.7.0.41: IP 192.168.44.1 >
192.168.58.1: ICMP echo request, id 21475, seq
82, length 64 (ipip-proto-4)
12:01:27.221219 (authentic,confidential): SPI 0xc2e51929: IP 192.168.44.1 >
192.168.58.1: ICMP echo request, id 21475, seq 82, length 64
12:01:28.241035 (authentic,confidential): SPI 0xc2e51929: IP 10.7.0.12 >
10.7.0.41: IP 192.168.44.1 >
192.168.58.1: ICMP echo request, id 21475, seq
83, length 64 (ipip-proto-4)
12:01:28.241039 (authentic,confidential): SPI 0xc2e51929: IP 192.168.44.1 >
192.168.58.1: ICMP echo request, id 21475, seq 83, length 64
12:01:29.251052 (authentic,confidential): SPI 0xc2e51929: IP 10.7.0.12 >
10.7.0.41: IP 192.168.44.1 >
192.168.58.1: ICMP echo request, id 21475, seq
84, length 64 (ipip-proto-4)
12:01:29.251056 (authentic,confidential): SPI 0xc2e51929: IP 192.168.44.1 >
192.168.58.1: ICMP echo request, id 21475, seq 84, length 64
12:01:30.260935 (authentic,confidential): SPI 0xc2e51929: IP 10.7.0.12 >
10.7.0.41: IP 192.168.44.1 >
192.168.58.1: ICMP echo request, id 21475, seq
85, length 64 (ipip-proto-4)
12:01:30.260938 (authentic,confidential): SPI 0xc2e51929: IP 192.168.44.1 >
192.168.58.1: ICMP echo request, id 21475, seq 85, length 64
12:01:31.271012 (authentic,confidential): SPI 0xc2e51929: IP 10.7.0.12 >
10.7.0.41: IP 192.168.44.1 >
192.168.58.1: ICMP echo request, id 21475, seq
86, length 64 (ipip-proto-4)
12:01:31.271022 (authentic,confidential): SPI 0xc2e51929: IP 192.168.44.1 >
192.168.58.1: ICMP echo request, id 21475, seq 86, length 64