[Openswan dev] Error building klips-ipv6 (missing include?)

David McCullough david_mccullough at mcafee.com
Mon Oct 11 17:45:11 EDT 2010


Jivin Harald Jenny lays it down ...
> On Mon, Oct 11, 2010 at 12:28:34PM -0400, Paul Wouters wrote:
> > On Mon, 11 Oct 2010, Ruben Laban wrote:
> > 
> > > I also noticed the mtu is quite huge. I wonder if that could interfere with
> > > pmtud somehow?
> > 
> > MTU's are huge so that fragmentation never happens on the virtual devices,
> > only on the real physical devices.
> > 
> > > More important (to me at least) is that I still need to do:
> > >
> > > # ip addr add 2a02:bd0:abcd:3::20/64 dev ipsec0
> > > # ipsec whack --listen
> > >
> > > before pluto starts listening on the IPv6 address.
> > 
> > Is 2a02:bd0:abcd:3::20/64 an address that's configured as a real IP address
> > on a real physical interface? If so, it should always show up in the listen
> > list. Can you give me a plutodebug=all of "ipsec setup start"?
> 
> Shouldn't this be done by tncfg? Maybe there lies the source of the problem?

Yes,  but if "ipsec setup start" runs before the interface has an IPv6
address,  then it won't be picked up.

Cheers,
Davidm

-- 
David McCullough,      david_mccullough at mcafee.com,  Ph:+61 734352815
McAfee - SnapGear      http://www.mcafee.com         http://www.uCdot.org


More information about the Dev mailing list