[AusNOG] IPsec VPN over 4G telstra issue

Sam McLeod ausnog at smcleod.net
Thu Sep 20 11:07:18 EST 2018


I'll just leave this here... https://web-in-security.blogspot.com/2018/08/practical-bleichenbacher-attacks-on-ipsec-ike.html <https://web-in-security.blogspot.com/2018/08/practical-bleichenbacher-attacks-on-ipsec-ike.html>

--
Sam McLeod
https://smcleod.net
https://twitter.com/s_mcleod

Words are my own opinions and do not necessarily represent those of my employer or partners.

> On 20 Sep 2018, at 11:03 am, Alex Samad <alex at samad.com.au> wrote:
> 
> Do we know what the issue is ?
> Is it just the IKE packets or are there other packets disappearing 
> 
> We use PA's ipsec vpn tech so ipsec inside udp from memory - wondering if they are filter / intercepting or ?
> 
> A
> 
> On Thu, 20 Sep 2018 at 09:46, Russell Langton <russell3901 at gmail.com <mailto:russell3901 at gmail.com>> wrote:
> Thanks Mat, its being worked on.
> 
> On Thu, 20 Sep. 2018, 9:32 am Mat van den Hoogen, <Mat at mimp.com <mailto:Mat at mimp.com>> wrote:
> We are experiencing the same on a few of our services, nothing has come back up though for us yet :(
> 
> —Mat
> 
> On 19 Sep 2018, at 8:11 pm, Russell Langton <russell3901 at gmail.com <mailto:russell3901 at gmail.com>> wrote:
> 
>> Hi All,
>> 
>> I'll reach out to some of you for details of the services impacted and get it in front of the right people to progress.
>> 
>> On Wed, Sep 19, 2018 at 5:20 PM Peter Tiggerdine <ptiggerdine at gmail.com <mailto:ptiggerdine at gmail.com>> wrote:
>> ROFL! THAT'S GOLD!!
>> 
>> Dutton Button!!
>> 
>> Regards,
>> 
>> Peter Tiggerdine
>> 
>> GPG Fingerprint: 2A3F EA19 F6C2 93C1 411D 5AB2 D5A8 E8A8 0E74 6127
>> 
>> 
>> On Wed, Sep 19, 2018 at 5:18 PM Matt Palmer <mpalmer at hezmatt.org <mailto:mpalmer at hezmatt.org>> wrote:
>> On 19 Sep 2018, at 4:33 pm, Dino Sosic <Dino.Sosic at datacom.com.au <mailto:Dino.Sosic at datacom.com.au>> wrote:
>> > Apparently Telstra confirmed today that there are issues with forming VPN
>> > IPsecs over 4G SIMs on telstra.internet APN. Anyone experiencing the same
>> > or knows anything about it? I have multiple sites down. IKE packets simply
>> > not making it to the other side.
>> 
>> Uh oh, looks like someone accidentally lent on the Dutton Button.
>> 
>> - Matt
>> 
>> _______________________________________________
>> AusNOG mailing list
>> AusNOG at lists.ausnog.net <mailto:AusNOG at lists.ausnog.net>
>> http://lists.ausnog.net/mailman/listinfo/ausnog <http://lists.ausnog.net/mailman/listinfo/ausnog>
>> _______________________________________________
>> AusNOG mailing list
>> AusNOG at lists.ausnog.net <mailto:AusNOG at lists.ausnog.net>
>> http://lists.ausnog.net/mailman/listinfo/ausnog <http://lists.ausnog.net/mailman/listinfo/ausnog>
>> _______________________________________________
>> AusNOG mailing list
>> AusNOG at lists.ausnog.net <mailto:AusNOG at lists.ausnog.net>
>> http://lists.ausnog.net/mailman/listinfo/ausnog <http://lists.ausnog.net/mailman/listinfo/ausnog>
> _______________________________________________
> AusNOG mailing list
> AusNOG at lists.ausnog.net <mailto:AusNOG at lists.ausnog.net>
> http://lists.ausnog.net/mailman/listinfo/ausnog <http://lists.ausnog.net/mailman/listinfo/ausnog>
> _______________________________________________
> AusNOG mailing list
> AusNOG at lists.ausnog.net
> http://lists.ausnog.net/mailman/listinfo/ausnog

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ausnog.net/pipermail/ausnog/attachments/20180920/7e292b06/attachment.html>


More information about the AusNOG mailing list