[strongSwan] Query: IKEv2 IPv6 packets on port 4500

Mukesh Yadav write2mukesh84 at gmail.com
Wed Nov 13 05:47:09 CET 2013


Hi,

I have a query regarding standard behavior  for IKEv2 IPv6 packets on port
4500.
Although NAT is not required in IPv6 case, RFC doesn't explicitly prohibit
IPv6 packets on UDp port 4500.

Want to know strong-swan behavior in same scenario. Does Strong-swan
process IPv6 packet on UDP port 4500?


RFC 5996 reference
2.  IKE Protocol Details and Variations
IKE normally listens and sends on UDP port 500, though IKE messages
   may also be received on UDP port 4500 with a slightly different
   format (see Section 2.23)

2.23.  NAT Traversal
An initiator can use port 4500 for both IKE and ESP, regardless of
   whether or not there is a NAT, even at the beginning of IKE


Thanks
Mukesh
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20131113/8c23c930/attachment.html>


More information about the Users mailing list