[Openswan Users] KLIPS module not loaded

David Clymer dclyme at hrcsb.org
Thu Oct 14 10:19:00 CEST 2004


On Wed, 2004-10-13 at 05:43, Ulrich Lauther wrote:
> Hi,
> 
> I compiled kernel 2.6.8.1 with option shown below, did in openswan-2.2.0:
> 	make programs
> 	make install
> 
> When I do: "ipsec setup start", ipsec is started without error messages,
> but
> 	ipsec setup status
> 
> gives me:
> 
> 	IPsec running
> 	but...
> 	KLIPS module is not loaded!
> 
> any idea what I did wrong?
> 

Are you sure you built it as a module? If you compiled it statically
into the kernel as indicated by the options below, you wouldnt see a
module, since none would need to be loaded.

> CONFIG_NET=y
> 
> CONFIG_PACKET=y
> CONFIG_NETLINK_DEV=y
> CONFIG_UNIX=y
> CONFIG_NET_KEY=y
> CONFIG_INET=y
> CONFIG_INET_AH=y
> CONFIG_INET_ESP=y
> CONFIG_INET_IPCOMP=y
> 
> CONFIG_IPV6=y
> CONFIG_IPV6_PRIVACY=y
> CONFIG_INET6_AH=y
> CONFIG_INET6_ESP=y
> CONFIG_INET6_IPCOMP=y
> CONFIG_IPV6_TUNNEL=y
> CONFIG_NETFILTER=y
> 
> CONFIG_IP_NF_NAT_NEEDED=y
> CONFIG_IP_NF_COMPAT_IPCHAINS=y
> 
> CONFIG_XFRM=y
> CONFIG_XFRM_USER=y
> 
> CONFIG_NETDEVICES=y
> CONFIG_DUMMY=m
> 
> CONFIG_CRYPTO=y
> CONFIG_CRYPTO_HMAC=y
> CONFIG_CRYPTO_NULL=y
> CONFIG_CRYPTO_MD4=y
> CONFIG_CRYPTO_MD5=y
> CONFIG_CRYPTO_SHA1=y
> CONFIG_CRYPTO_SHA256=y
> CONFIG_CRYPTO_SHA512=y
> CONFIG_CRYPTO_DES=y
> CONFIG_CRYPTO_BLOWFISH=y
> CONFIG_CRYPTO_TWOFISH=y
> CONFIG_CRYPTO_SERPENT=y
> CONFIG_CRYPTO_AES_586=y
> CONFIG_CRYPTO_CAST5=y
> CONFIG_CRYPTO_CAST6=y
> CONFIG_CRYPTO_TEA=y
> CONFIG_CRYPTO_ARC4=y
> CONFIG_CRYPTO_KHAZAD=y
> CONFIG_CRYPTO_DEFLATE=y
> CONFIG_CRYPTO_MICHAEL_MIC=y
> CONFIG_CRYPTO_CRC32C=y
> CONFIG_CRYPTO_TEST=y

I've not used KLIPS on more recent kernels, but on the one machine I'm
running KLIPS & FreeS/WAN on, I've got a list of options like this in my
kernel config:

herme:/boot# cat config-2.4.18-freeswan |grep IPSEC
CONFIG_IPSEC=y
CONFIG_IPSEC_IPIP=y
CONFIG_IPSEC_AH=y
CONFIG_IPSEC_AUTH_HMAC_MD5=y
CONFIG_IPSEC_AUTH_HMAC_SHA1=y
CONFIG_IPSEC_ESP=y
CONFIG_IPSEC_ENC_3DES=y
CONFIG_IPSEC_EXT=y
# CONFIG_IPSEC_EXT_MD5 is not set
CONFIG_IPSEC_EXT_RIPEMD=m
# CONFIG_IPSEC_EXT_SHA1 is not set
CONFIG_IPSEC_EXT_SHA2=m
# CONFIG_IPSEC_EXT_3DES is not set
# CONFIG_IPSEC_EXT_AES_OPT is not set
CONFIG_IPSEC_EXT_AES=m
CONFIG_IPSEC_EXT_BLOWFISH=m
CONFIG_IPSEC_EXT_CAST=m
CONFIG_IPSEC_EXT_NULL=m
CONFIG_IPSEC_EXT_SERPENT=m
CONFIG_IPSEC_EXT_TWOFISH=m
CONFIG_IPSEC_IPCOMP=y
CONFIG_IPSEC_DEBUG=y

are you certain you are using KLIPS and not just 2.6 native IPsec?

-davidc



More information about the Users mailing list