[Openswan dev] [PATCH] Add NON-IKE support for 26sec

Ken Bantoft ken at xelerance.com
Wed Jun 2 05:12:02 CEST 2004


On Tue, 1 Jun 2004, Nate Carlson wrote:

> On Tue, 1 Jun 2004, Ken Bantoft wrote:
> > I'd heard about this, but haven't had time to check out the latest SuSE
> > patches yet.
> > 
> > Thanks for the patch, it's in HEAD now, and I've put it in the 2.1.x
> > branch as well, incase we do another release from that branch.
> 
> Note that this patch to Openswan breaks things on a stock 2.6 kernel
> without the SuSE patches, talking to a SFS 1.99 box - get the dreaded
> unhandled udp encap type error. Maybe need some logic to figure out if the 
> SuSE patches are applied to the kernel or not?

Insert rant about vendor patched kernels here - they make our lives a 
nightmare, and waste far too much of our time.  Does the stock kernel suck 
so much these days?

I guess I'll back it out for now, and we can see if the SuSE patch makes 
it into the Linus kernels or something.


> It works fine with a 2.4.26 kernel with the backported 26sec support, and
> the SuSE patch applied.
> 
> I also tried it on the same 2.4.26 kernel with KLIPS instead of 26sec (so
> KLIPS using the 26sec NAT-T patches with the SuSE patch); I do not receive
> a UDP Encaps error (like I previously did without the SuSE patch applied
> to the kernel), but traffic over the tunnel still doesn't work.


-- 
Ken Bantoft			VP Business Development
ken at xelerance.com		Xelerance Corporation
sip://toronto.xelerance.com	http://www.xelerance.com

The future is here. It's just not evenly distributed yet. 
        -- William Gibson




More information about the Dev mailing list