[Openswan dev] Error building klips-ipv6 (missing include?)
David McCullough
david_mccullough at mcafee.com
Tue Aug 31 10:02:27 EDT 2010
Jivin Ruben Laban lays it down ...
> Hi David,
>
> On Wednesday 25 August 2010 at 13:36 (CET), David McCullough wrote:
> > Jivin Ruben Laban lays it down ...
> >
> > > On Wednesday 25 August 2010 at 13:12 (CET), Ruben Laban wrote:
> > > > Ping6 from east to west doesn't seem to work (yet), but I'm still
> > > > investigating that scenario.
> > >
> > > Scratch that. It was a missing route to west (via ipsec0). A updown.klips
> > > issue I take.
> >
> > Could be, I have my own bits there as well. I am working on getting the
> > klips scrips into line at the moment.
>
> Progressing nicely in that area. The ipsec setup parts seems to be working
> just fine with latest git.
>
> > I'll also have a look at the byte swap thing tomorrow as well and see
> > what I can learn,
>
> This has been fixed in the meantime as well.
>
> To summarize I see 2 "major" issues left:
>
> * "messed" up destination mac addresses on outbound traffic (seen by tcpdump on
> ipsecX)
Yeah, I have reproduced that but not looked at it any further.
> * _updown.klips doesn't take care of adding IPv6 routes yet
>
> When the 2nd issue were to be solved, I'll see if I can run some "production"
> tests with it (my home-work VPN runs over IPv6 currently, using
> openswan/netkey obviously).
I have this done, just not tested yet, a couple of other things taking my
time. Hopefully soon. Just checking on a another random "short packets"
problem that seems a bit hit or miss as to whether it happens or not.
Slow and steady ;-)
Thanks for the testing and feedback,
Cheers,
Davidm
--
David McCullough, david_mccullough at mcafee.com, Ph:+61 734352815
McAfee - SnapGear http://www.mcafee.com http://www.uCdot.org
More information about the Dev
mailing list