[Openswan dev] Error building klips-ipv6 (missing include?)

David McCullough david_mccullough at mcafee.com
Tue Aug 31 10:02:27 EDT 2010


Jivin Ruben Laban lays it down ...
> Hi David,
> 
> On Wednesday 25 August 2010 at 13:36 (CET), David McCullough wrote:
> > Jivin Ruben Laban lays it down ...
> > 
> > > On Wednesday 25 August 2010 at 13:12 (CET), Ruben Laban wrote:
> > > > Ping6 from east to west doesn't seem to work (yet), but I'm still
> > > > investigating that scenario.
> > > 
> > > Scratch that. It was a missing route to west (via ipsec0). A updown.klips
> > > issue I take.
> > 
> > Could be,  I have my own bits there as well.  I am working on getting the
> > klips scrips into line at the moment.
> 
> Progressing nicely in that area. The ipsec setup parts seems to be working 
> just fine with latest git. 
> 
> > I'll also have a look at the byte swap thing tomorrow as well and see
> > what I can learn,
> 
> This has been fixed in the meantime as well.
> 
> To summarize I see 2 "major" issues left:
> 
> * "messed" up destination mac addresses on outbound traffic (seen by tcpdump on 
> ipsecX)

Yeah,  I have reproduced that but not looked at it any further.

> * _updown.klips doesn't take care of adding IPv6 routes yet
> 
> When the 2nd issue were to be solved, I'll see if I can run some "production" 
> tests with it (my home-work VPN runs over IPv6 currently, using 
> openswan/netkey obviously).

I have this done,  just not tested yet,  a couple of other things taking my
time.  Hopefully soon.  Just checking on a another random "short packets"
problem that seems a bit hit or miss as to whether it happens or not.

Slow and steady ;-)

Thanks for the testing and feedback,

Cheers,
Davidm


-- 
David McCullough,      david_mccullough at mcafee.com,  Ph:+61 734352815
McAfee - SnapGear      http://www.mcafee.com         http://www.uCdot.org


More information about the Dev mailing list