<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
<title></title>
</head>
<body bgcolor="#ffffff" text="#000000">
Herbert Xu wrote:
<blockquote cite="midE1DVyxv-0005TP-00@gondolin.me.apana.org.au"
type="cite">
<pre wrap="">Phillip T. George <a class="moz-txt-link-rfc2396E" href="mailto:phillip@eacsi.com"><phillip@eacsi.com></a> wrote:
</pre>
<blockquote type="cite">
<pre wrap="">This information was pulled from:
<a class="moz-txt-link-freetext" href="http://www.openswan.org/docs/local/README.Kernel26">http://www.openswan.org/docs/local/README.Kernel26</a>
"
* compression seems to be incompatible between KLIPS and the 2.6 ipsec
code. Since we believe the 2.6 ipsec code is wrong, we cannot fix this.
If you get a successful IKE negotiation and can send ESP packets, but
never get replies, compile KLIPS without CONFIG_IPSEC_IPCOMP. There is
currently no runtime switch to disable compression. Note that setting
compress=no is not enough; it just means we do not announce compression,
but we'll still do it if the other end requests it.
"
</pre>
</blockquote>
<pre wrap=""><!---->
</pre>
<blockquote type="cite">
<pre wrap="">So the question is, as stated above: Is there a work around or a direct
fix on getting compression to work with kernel version 2.6?
</pre>
</blockquote>
<pre wrap=""><!---->
Just ignore it, it's totally wrong.
Cheers,
</pre>
</blockquote>
<br>
Strange. I can only get a GOOD connection if I turn compression off on
both sides. Otherwise I can only get a small amount of data between
both points. (2 FC3 firewalls with same software versions of
everything)<br>
<br>
-Phillip<br>
</body>
</html>