Merge lp:~christof-mroz/hipl/midauth-nfqueue-fix into lp:hipl
Proposed by
Christof Mroz
Status: | Merged |
---|---|
Merged at revision: | 6464 |
Proposed branch: | lp:~christof-mroz/hipl/midauth-nfqueue-fix |
Merge into: | lp:hipl |
Diff against target: |
111 lines (+35/-29) 1 file modified
hipfw/rewrite.c (+35/-29) |
To merge this branch: | bzr merge lp:~christof-mroz/hipl/midauth-nfqueue-fix |
Related bugs: |
Reviewer | Review Type | Date Requested | Status |
---|---|---|---|
Miika Komu | Approve | ||
Review via email: mp+288588@code.launchpad.net |
Description of the change
This is a fix for Bug #1554072, based on an earlier fix which seemed to work. Keeping this as a separate branch since I didn't have a chance to test it yet.
To post a comment you must log in.
Tested, works (see the log snippet below)! Please merge and commit.
debug(hipfw/ hipfw.c: 1060@filter_ hip): falling back to default HIP/ESP behavior, target 1 conntrack. c:2059@ get_tuple_ by_hits) : connection found, conntrack. c:1736@ check_packet) : check packet: type 3 midauth. c:345@hipfw_ midauth_ verify_ challenge) : Correct CHALLENGE_RESPONSE found conntrack. c:1065@ fw_verify_ and_store_ host_id) : HI -> HIT mapping verified conntrack. c:1030@ fw_verify_ packet) : Signature successfully verified conntrack. c:310@get_ esp_address) : Looking for entry with addr: : 172.17.0.2 conntrack. c:328@get_ esp_address) : no matching entry found conntrack. c:508@update_ esp_address) : address: ::ffff:172.17.0.2 dlist.c: 137@append_ to_list) : List is empty inserting first node conntrack. c:1791@ check_packet) : udp_encap_ hdr=0x6adb94 tuple=0x25c4c90 err=1 conntrack. c:1797@ check_packet) : UDP src port 10500 conntrack. c:1798@ check_packet) : UDP dst port 10500 hipfw.c: 1656@fw_ handle_ packet) : === Verdict: allow modified packet === rewrite. c:383@allow_ modified_ packet) : Packet accepted with modifications
debug(hipfw/
debug(hipfw/
debug(hipfw/
info(hipfw/
info(hipfw/
debug(hipfw/
debug(hipfw/
debug(hipfw/
debug(hipfw/
debug(hipfw/
debug(hipfw/
debug(hipfw/
debug(hipfw/
debug(hipfw/