Re: [ovs-discuss] VXLAN over IPSec - what's wrong

2018-10-08 Thread Sebastian Pitei
Hi Qiuyu, Yes, if I try to ping from fd::10 to fd::11 the ICMP gets through and is encrypted. Seb -Original Message- From: Qiuyu Xiao Sent: Monday, October 8, 2018 4:01 PM To: Sebastian Pitei Cc: ovs-discuss@openvswitch.org Subject: Re: [ovs-discuss] VXLAN over IPSec - what's wrong

Re: [ovs-discuss] VXLAN over IPSec - what's wrong

2018-10-07 Thread Sebastian Pitei
- From: Sebastian Pitei Sent: Sunday, October 7, 2018 8:03 PM To: Qiuyu Xiao Cc: ovs-discuss@openvswitch.org Subject: RE: [ovs-discuss] VXLAN over IPSec - what's wrong Hi Qiuyu, Thanks a lot for your suggestions. In order to better troubleshoot this, let me state my understanding of the whole

Re: [ovs-discuss] VXLAN over IPSec - what's wrong

2018-10-07 Thread Sebastian Pitei
and the destination IP address in the OVS flow the packet leaves the OVS binary. -Strongswan should now "catch" the IP traffic (as specified by the traffic selectors) and encrypt the packet. -Original Message- From: Qiuyu Xiao Sent: Thursday, September 20, 2018 1:13 AM To: Sebas

[ovs-discuss] VXLAN over IPSec - what's wrong

2018-09-17 Thread Sebastian Pitei
Hi everyone, I'm trying to build a simple OVS setup as follows: -two OVS switches (on separate machines), both having one physical port (enp0s10) and a virtual one (vxlan0), on the same br0 bridge. -each br0 has a manually set IPv6 address that's being used as source and destination for the