Nevim, mozna jo a odpovidalo by to časově. Tunel (ipsec,wg)má vždy vnějši a vnitřní "část" (čistý provoz v virt. rozhraní a zašifrovaný na vnějšim. Něco jako cipherpaylod a plain payload)
Ale. To je UDP na portu 4500.( to vidí i routr)
Zahada je ale, proč by se na wlan0 bral tento "čistý provoz".
Nenatrefil jsem na hřebíčk?ipsec nerozumim.
Zde je zaznam: jsou tu 2 druhy. A tsky port uz neni 52020 ale 52030
00:42:00.760911 IP (tos 0xb8, ttl 59, id 43617, offset 0, flags [none], proto ESP (50), length 64)
10.65.183.200 > 10.15.239.107: ESP(spi=0x78a687f1,seq=0x15), length 44
00:42:15.634648 IP (tos 0xb8, ttl 59, id 49319, offset 0, flags [none], proto ESP (50), length 320)
10.65.183.200 > 10.15.239.107: ESP(spi=0x78a687f1,seq=0x16), length 300
00:42:17.433118 IP (tos 0xb8, ttl 59, id 25776, offset 0, flags [none], proto ESP (50), length 352)
10.65.183.200 > 10.15.239.107: ESP(spi=0x78a687f1,seq=0x17), length 332
00:42:17.466228 IP (tos 0xb8, ttl 59, id 37040, offset 0, flags [none], proto ESP (50), length 788)
10.65.183.200 > 10.15.239.107: ESP(spi=0x78a687f1,seq=0x18), length 768
00:42:17.611056 IP (tos 0xb8, ttl 59, id 20913, offset 0, flags [none], proto ESP (50), length 64)
10.65.183.200 > 10.15.239.107: ESP(spi=0x78a687f1,seq=0x19), length 44
.....
00:41:02.819643 IP (tos 0xb8, ttl 54, id 0, offset 0, flags [none], proto UDP (17), length 72)
10.65.183.201.20128 > 10.15.239.107.50030: [udp sum ok] UDP, length 44
00:41:02.838657 IP (tos 0xb8, ttl 54, id 0, offset 0, flags [none], proto UDP (17), length 72)
10.65.183.201.20128 > 10.15.239.107.50030: [udp sum ok] UDP, length 44
00:41:02.858689 IP (tos 0xb8, ttl 54, id 0, offset 0, flags [none], proto UDP (17), length 72)
10.65.183.201.20128 > 10.15.239.107.50030: [udp sum ok] UDP, length 44
00:41:02.877737 IP (tos 0xb8, ttl 54, id 0, offset 0, flags [none], proto UDP (17), length 72)
10.65.183.201.20128 > 10.15.239.107.50030: [udp sum ok] UDP, length 44
00:41:02.900469 IP (tos 0xb8, ttl 54, id 0, offset 0, flags [none], proto UDP (17), length 72)
10.65.183.201.20128 > 10.15.239.107.50030: [udp sum ok] UDP, length 44
00:41:02.929173 IP (tos 0xb8, ttl 54, id 0, offset 0, flags [none], proto UDP (17), length 72)
10.65.183.201.20128 > 10.15.239.107.50030: [udp sum ok] UDP, length 44
00:41:02.936772 IP (tos 0xb8, ttl 54, id 0, offset 0, flags [none], proto UDP (17), length 72)
10.65.183.201.20128 > 10.15.239.107.50030: [udp sum ok] UDP, length 44
bug /vlastnost packetfiltru( tcpdump) pokud by platila ta hypotez ze jde o vybaleny ipsec ?