Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-11-02 Thread Herbert Xu
Evan Gilman wrote: > > I tried to find a reference to the previous report of aesni-intel > causing IPSec corruption under Xen - I'd be interested to read it if > anyone here has it on hand. For now, we are looking to blacklist > aesni-intel as we have no other suitable solution, and when combined

Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-11-02 Thread Herbert Xu
Evan Gilman e...@pagerduty.com wrote: I tried to find a reference to the previous report of aesni-intel causing IPSec corruption under Xen - I'd be interested to read it if anyone here has it on hand. For now, we are looking to blacklist aesni-intel as we have no other suitable solution, and

Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-10-30 Thread Evan Gilman
Indeed, I am using aesni-intel. I have again been bitten by this problem, but do not have the cycles to pinpoint the kernel version in which the trouble was introduced. I have done a bit more research, and have found that hosts running under Xen 4.4.2 are not affected (regardless of kernel

Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-10-30 Thread Evan Gilman
Indeed, I am using aesni-intel. I have again been bitten by this problem, but do not have the cycles to pinpoint the kernel version in which the trouble was introduced. I have done a bit more research, and have found that hosts running under Xen 4.4.2 are not affected (regardless of kernel

Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-06-30 Thread Herbert Xu
On Mon, Jun 30, 2014 at 01:33:24PM +0200, Steffen Klassert wrote: > Ccing netdev. > > On Thu, Jun 26, 2014 at 02:12:30PM -0700, Evan Gilman wrote: > >Hi all > >We have a couple Ubuntu 10.04 hosts with kernel version 3.14.5 which are > >experiencing TCP payload corruption when using

Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-06-30 Thread Steffen Klassert
Ccing netdev. On Thu, Jun 26, 2014 at 02:12:30PM -0700, Evan Gilman wrote: >Hi all >We have a couple Ubuntu 10.04 hosts with kernel version 3.14.5 which are >experiencing TCP payload corruption when using IPSec in NAT-T transport >mode. All are running under Xen at third party

Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-06-30 Thread Steffen Klassert
Ccing netdev. On Thu, Jun 26, 2014 at 02:12:30PM -0700, Evan Gilman wrote: Hi all We have a couple Ubuntu 10.04 hosts with kernel version 3.14.5 which are experiencing TCP payload corruption when using IPSec in NAT-T transport mode. All are running under Xen at third party

Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-06-30 Thread Herbert Xu
On Mon, Jun 30, 2014 at 01:33:24PM +0200, Steffen Klassert wrote: Ccing netdev. On Thu, Jun 26, 2014 at 02:12:30PM -0700, Evan Gilman wrote: Hi all We have a couple Ubuntu 10.04 hosts with kernel version 3.14.5 which are experiencing TCP payload corruption when using IPSec in

Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-06-26 Thread Evan Gilman
Hi all We have a couple Ubuntu 10.04 hosts with kernel version 3.14.5 which are experiencing TCP payload corruption when using IPSec in NAT-T transport mode. All are running under Xen at third party providers. When communicating with other hosts using IPSec, we see that these corrupt TCP PDUs are

Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-06-26 Thread Evan Gilman
Hi all We have a couple Ubuntu 10.04 hosts with kernel version 3.14.5 which are experiencing TCP payload corruption when using IPSec in NAT-T transport mode. All are running under Xen at third party providers. When communicating with other hosts using IPSec, we see that these corrupt TCP PDUs are