[v6ops] OSX 10.8 failures with Cisco Anyconnect VPN client

Mark Boolootian <booloo@ucsc.edu> Thu, 16 May 2013 23:25 UTC

Return-Path: <booloo@ucsc.edu>
X-Original-To: v6ops@ietfa.amsl.com
Delivered-To: v6ops@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 98C2511E80D5 for <v6ops@ietfa.amsl.com>; Thu, 16 May 2013 16:25:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.977
X-Spam-Level:
X-Spam-Status: No, score=-2.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aDTsiDpFExlP for <v6ops@ietfa.amsl.com>; Thu, 16 May 2013 16:24:56 -0700 (PDT)
Received: from mail-qe0-f50.google.com (mail-qe0-f50.google.com [209.85.128.50]) by ietfa.amsl.com (Postfix) with ESMTP id 55B2921F8E46 for <v6ops@ietf.org>; Thu, 16 May 2013 16:24:55 -0700 (PDT)
Received: by mail-qe0-f50.google.com with SMTP id x7so106171qeu.37 for <v6ops@ietf.org>; Thu, 16 May 2013 16:24:55 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ucsc.edu; s=ucsc-google; h=mime-version:x-received:date:message-id:subject:from:to :content-type; bh=HYKDqmYea+0sZ2DF7T/g9CrVk9CoD25I0jv3jjjSVog=; b=Af2j3gFJq7Mbezz5YWXWWy7UnPyi8xFkfvdBcLc3fHQnfyLU0m7E4h4U7ez3cgXp9E NUGtFuFld72L8je6g2xZEtsHfWwjD06UonCSArVsGvqVjz7t1kMIlvzuQBAhgEXm2StE ddezxPkS+rgjQcA1aIVh2j3LHJRjQqcx64jfI=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:x-received:date:message-id:subject:from:to :content-type:x-gm-message-state; bh=HYKDqmYea+0sZ2DF7T/g9CrVk9CoD25I0jv3jjjSVog=; b=VM56v8FrbRqnDPHJu3kVodU6GHqgz2zgM4WCDt/FfFkS/lYPLXiZy7KMYGcb3ZrsUd tOkJ2/c9AOPf4Rx042k8jtvY/mV3nB5uThvJa5P0rtCbSOkPY8imDFbK8mlaOfQRW1aK a8MpZ7zs1D3AjtsdY9WKV8XtxKE+CkoVyz6ipGuPQqN/wgToowmR63yNDzWxwWi/UIDC gslmk3YXmwFvBFBuCOuJd9Bquj27MVE6JP+FTFbY49AkOUigu5zbM0DyBYCfNLYG/HLw 3+bt/SuUCdICzH3hcwD6U10Gy50x9uQ2RzqQPgEPDbNouU7AXx7anFzVmzIsFCPqCqH6 5t6g==
MIME-Version: 1.0
X-Received: by 10.49.119.196 with SMTP id kw4mr39511336qeb.35.1368746695451; Thu, 16 May 2013 16:24:55 -0700 (PDT)
Received: by 10.49.85.65 with HTTP; Thu, 16 May 2013 16:24:55 -0700 (PDT)
Date: Thu, 16 May 2013 16:24:55 -0700
Message-ID: <CAMCLrkEzXBZdVfx=gUBb=4P=pEwAkE4_Q3wJ-kGNSn9p7QWT7g@mail.gmail.com>
From: Mark Boolootian <booloo@ucsc.edu>
To: v6ops@ietf.org
Content-Type: text/plain; charset="ISO-8859-1"
X-Gm-Message-State: ALoCoQll0Bv7Dkqiq/rrQgkPHpnAa5KMFnl+3V5IKr0H+hQq9aYGI1aevmdz4NVFROeAObCew1x1
Subject: [v6ops] OSX 10.8 failures with Cisco Anyconnect VPN client
X-BeenThere: v6ops@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: v6ops discussion list <v6ops.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/v6ops>, <mailto:v6ops-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/v6ops>
List-Post: <mailto:v6ops@ietf.org>
List-Help: <mailto:v6ops-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/v6ops>, <mailto:v6ops-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 May 2013 23:25:00 -0000

I've got a Macbook running 10.8.3.  It has a v6 GUA, and a public v4
address.  Works dandy.

Now I bring up a VPN tunnel with Cisco Anyconnect Secure Mobility
Client (v3.1).  The VPN is IPv4 only.  If I point Safari or Chrome at
www.google.com, I get back nothing.  A little poking shows that DNS
AAAA queries are being issued.  As near as I can tell, that shouldn't
be happening, since the tunnel is v4 only.

Whose bug is this likely to be?  It looks to me like a problem with
the resolver library looking at the physical interface, instead of the
tunnel interface, for determining how to query DNS.  I haven't opened
a ticket with Cisco yet, but plan to.

Insight appreciated,
mark