
piero.ottuzzi at omnys
Nov 19, 2004, 10:48 AM
Post #9 of 11
(751 views)
Permalink
|
Hi, sorry for stressing this point... but I would like to understand what is really happening.... This morning I started and used vpnc regularly and disconnected OK. The I needed to re-enter VPN but then nothing worked OK. vpnc-connect said it was connected. As you suggested I made a ping towards a remote vpn machine and then I run tcpdump: [root [at] ap piero]# tcpdump -vv -i tun0 tcpdump: listening on tun0, link-type LINUX_SLL (Linux cooked), capture size 96 bytes 10:35:15.489341 IP (tos 0x0, ttl 64, id 529, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 530 10:35:15.526643 IP (tos 0x0, ttl 64, id 22148, offset 0, flags [DF], length: 73) 192.168.16.102.33265 > 213.21.141.2.domain: [udp sum ok] 44168+ PTR? 102.16.168.192.in-addr.arpa. (45) 10:35:16.488862 IP (tos 0x0, ttl 64, id 530, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 531 10:35:17.456691 IP (tos 0x0, ttl 64, id 24079, offset 0, flags [DF], length: 63) 192.168.16.102.33266 > 62.152.33.7.domain: [udp sum ok] 3025+ A? scs.msg.yahoo.com. (35) 10:35:17.488665 IP (tos 0x0, ttl 64, id 531, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 532 10:35:18.488469 IP (tos 0x0, ttl 64, id 532, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 533 10:35:18.526421 IP (tos 0x0, ttl 64, id 25149, offset 0, flags [DF], length: 73) 192.168.16.102.33267 > 62.152.33.7.domain: [udp sum ok] 44168+ PTR? 102.16.168.192.in-addr.arpa. (45) 10:35:19.488216 IP (tos 0x0, ttl 64, id 533, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 534 10:35:20.488021 IP (tos 0x0, ttl 64, id 534, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 535 10:35:21.487825 IP (tos 0x0, ttl 64, id 535, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 536 10:35:22.487673 IP (tos 0x0, ttl 64, id 536, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 537 10:35:23.456633 IP (tos 0x0, ttl 64, id 30080, offset 0, flags [DF], length: 63) 192.168.16.102.33268 > 213.21.141.2.domain: [udp sum ok] 3025+ A? scs.msg.yahoo.com. (35) 10:35:23.487432 IP (tos 0x0, ttl 64, id 537, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 538 10:35:24.487570 IP (tos 0x0, ttl 64, id 538, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 539 10:35:24.526380 IP (tos 0x0, ttl 64, id 31150, offset 0, flags [DF], length: 73) 192.168.16.102.33269 > 213.21.141.2.domain: [udp sum ok] 44168+ PTR? 102.16.168.192.in-addr.arpa. (45) 10:35:25.487042 IP (tos 0x0, ttl 64, id 539, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 540 10:35:26.456866 IP (tos 0x0, ttl 64, id 33081, offset 0, flags [DF], length: 63) 192.168.16.102.33270 > 62.152.33.7.domain: [udp sum ok] 3025+ A? scs.msg.yahoo.com. (35) 10:35:26.486858 IP (tos 0x0, ttl 64, id 540, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 541 10:35:27.486734 IP (tos 0x0, ttl 64, id 541, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 542 10:35:27.527958 IP (tos 0x0, ttl 64, id 34152, offset 0, flags [DF], length: 73) 192.168.16.102.33271 > 62.152.33.7.domain: [udp sum ok] 44168+ PTR? 102.16.168.192.in-addr.arpa. (45) 10:35:28.486839 IP (tos 0x0, ttl 64, id 542, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 543 10:35:29.486272 IP (tos 0x0, ttl 64, id 543, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 544 10:35:30.486078 IP (tos 0x0, ttl 64, id 544, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 545 10:35:31.485930 IP (tos 0x0, ttl 64, id 545, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 546 10:35:32.456893 IP (tos 0x0, ttl 64, id 39082, offset 0, flags [DF], length: 63) 192.168.16.102.33272 > 213.21.141.2.domain: [udp sum ok] 3026+ A? scs.msg.yahoo.com. (35) 10:35:32.485737 IP (tos 0x0, ttl 64, id 546, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 547 10:35:33.485583 IP (tos 0x0, ttl 64, id 547, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 548 10:35:33.528359 IP (tos 0x0, ttl 64, id 40153, offset 0, flags [DF], length: 71) 192.168.16.102.33273 > 213.21.141.2.domain: [udp sum ok] 44169+ PTR? 2.141.21.213.in-addr.arpa. (43) 10:35:34.485346 IP (tos 0x0, ttl 64, id 548, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 549 10:35:35.458228 IP (tos 0x0, ttl 64, id 42084, offset 0, flags [DF], length: 63) 192.168.16.102.33274 > 62.152.33.7.domain: [udp sum ok] 3026+ A? scs.msg.yahoo.com. (35) 10:35:35.488084 IP (tos 0x0, ttl 64, id 549, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 550 10:35:36.487887 IP (tos 0x0, ttl 64, id 550, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 551 10:35:36.528975 IP (tos 0x0, ttl 64, id 43155, offset 0, flags [DF], length: 71) 192.168.16.102.33276 > 62.152.33.7.domain: [udp sum ok] 44169+ PTR? 2.141.21.213.in-addr.arpa. (43) 10:35:37.487691 IP (tos 0x0, ttl 64, id 551, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 552 10:35:38.487495 IP (tos 0x0, ttl 64, id 552, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 553 10:35:39.059661 IP (tos 0x0, ttl 64, id 45686, offset 0, flags [DF], length: 62) 192.168.16.102.33277 > 213.21.141.2.domain: [udp sum ok] 21200+ A? wpop12.libero.it. (34) 10:35:39.487299 IP (tos 0x0, ttl 64, id 553, offset 0, flags [DF], length: 84) 192.168.16.102 > cairoO: icmp 64: echo request seq 554 10:35:39.676286 IP (tos 0x10, ttl 64, id 40, offset 0, flags [DF], length: 76) 192.168.9.15.ntp > 193.204.114.233.ntp: [udp sum ok] NTPv4 client, strat 11, poll 10, prec -20 dist 0.000000, disp 0.012420, ref 127.127.1.0 [at] 3309845704 (2004/11/19 10:35:04) orig 3309844711.892676999 (2004/11/19 10:18:31) rec +2.045191999 xmt +1027.783578000 38 packets captured 216 packets received by filter 0 packets dropped by kernel My local address is 192.168.9.15; My "remote address" was 192.168.16.102. As you may see NO PACKET return from vpn connection to my PC (and a ping towards cairoO was running). Here is my route during vpn connection: [root [at] ap piero]# route Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface 217.169.119.1 192.168.9.2 255.255.255.255 UGH 0 0 0 eth0 192.168.9.0 * 255.255.255.0 U 0 0 0 eth0 default * 0.0.0.0 U 0 0 0 tun0 What is it going on? Ciaoo Piero Alle 18:56, mercoled? 17 novembre 2004, Maurice Massar ha scritto: > hi, > > On Wed, Nov 17, 2004 at 12:17:55PM +0100, Piero Ottuzzi wrote: > > Hi again, > > > > really can't remember where but I read somewhere that vpnc (or > > vpnc-connect) setup routing before the tunnel is really opened. > > I noted that vpnc always opens a working connection in the first tryout > > after a reboot but it not always opens a working connection afterward > > (sometimes yes, sometimes not as per thread title). > > > > Is there a way to be absolutely sure that the tunnel is open? > > Is there a way to know if the tunnel close for whatever reason? > > when vpnc returns, the "Config Script" is done, so the tunnel device > is fully set up and routing should be in place (this should be done > by the config script, vpnc-connect does that). > > I am relatively certain that the vpnc side is ready as soon as vpnc > backgrounds itself. > > Maybe using tcpdump could verfiy this. > > cu > maurice > _______________________________________________ > vpnc-devel mailing list > vpnc-devel [at] unix-ag > http://lists.unix-ag.uni-kl.de/mailman/listinfo/vpnc-devel > http://www.unix-ag.uni-kl.de/~massar/vpnc/ -- 'Stupid is as stupid does' - Forrest Gump GPG KeyID: 84AE988E Fingerprint: F0A0 CA2A 8D8F CC12 3F5E C04C D8D5 9DC3 84AE 988E gpg --keyserver x-hkp://search.keyserver.net:11371 --recv-key 84AE988E -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: not available Url : http://lists.unix-ag.uni-kl.de/pipermail/vpnc-devel/attachments/20041119/cc888188/attachment.pgp
|