[Openswan Users] saref patch

Paul Wouters paul at xelerance.com
Fri Nov 27 10:48:40 EST 2009

On Fri, 27 Nov 2009, Giovani Moda wrote:

> How does the mastX interface behaves? Do I have to set a interface for
> it to bind to, as I did to ipsecX? I'm asking because I noticed that it
> stays up even with openswan stopped, and it's IP is the one from my
> internal interface. I tried setting 'interfaces="mast0=eth0"' but it
> didn't make a difference.

If i remember correctly, it should have the IP of the external interface?

> Also, is openswan's native crypto required for saref?

NETKEY does not support saref.

> cryptoapi, and I don't get a kernel panic, but I have this error
> instead, both with protostack=klips and protostack=mast:

No one has tested saref with cryptoapi (or OCF) yet. There is no
reason it cannot be made to work with it, but we do not know yet
if there are any issues.


More information about the Users mailing list