Debugging UDP ESP failure

Daniel Lenski dlenski at gmail.com
Sat Jul 27 17:40:09 PDT 2024


On Sat, Jul 27, 2024 at 2:03 PM Karl O. Pinc <kop at karlpinc.com> wrote:
>
> > I put together a fix for this in
> > https://gitlab.com/openconnect/openconnect/-/commits/handle_GP_ESP_magic_address_corner_case
> >
> > Can you please build and test that? I don't have a real GP VPN that I
> > can test it on anymore, unfortunately.
>
> Works for me.  The output includes:
>
>   ESP session established with server
>   ESP tunnel connected; exiting HTTPS mainloop.
>   Configured as READACTEDIPV4NUMBER, with SSL disconnected and ESP established
>
> And I see the expected UDP traffic go through the firewall. Thanks!

Excellent, thanks. I was able to add some semi-automated tests thanks
to your detailed report here, and I've created an MR to fix it in the
next release at
https://gitlab.com/openconnect/openconnect/-/merge_requests/565



More information about the openconnect-devel mailing list