[Openswan Users] Openswan 2.6.26 + mast +saref + xl2pd

Paul Wouters paul at xelerance.com
Tue Jun 22 18:18:44 EDT 2010


On Tue, 22 Jun 2010, jww at ILSTechnology.com wrote:

> This is my first post on this, so please excuse if I do it incorrectly.
> I am attempting to reach the fellow in the June archives at
> http://lists.openswan.org/pipermail/users/2010-June/018896.html
>
> I had the identical problem with Centos 5.5 and so downloaded Openswan
> 2.6.27 source code.
> It compiled programs and then I got the error here.
> I then merely removed the line 2035 in ipsec_xmit.c and then was able to
> rebuild the module ipsec.ko.
> Also built the programs.

Okay.

> Now Centos 5.5 only includes from it's repository openswan 2.6.21.
> Can I safely use that openswan 2.6.21, or do I need to deploy the binaries
> from my 2.6.27 openswan build into my Centos 5.5.

If using klips, and doing l2tp, you will need the NAT-T patch for KLIPS.
There should be a nat-t patch for 2.6.21 on ftp.openswan.org.

> I know, I know, I don't need ipsec.ko becuz is is provided now by openswan.
> We have a legacy application that used ipsec.ko for some reason, and the
> original developers are not around.

KLIPS(ipsec.ko) is currently the only stack supporting SAref, however you
will also need to apply the two saref patches in the openswan tar ball in
patches/kernel/2.6.32/

I am not sure how well they will work on a 2.6.21 or 2.6.18 based kernel.
It might require some manual patching.

We will provide some kernel debs and rpms over the next week or two.

Paul


More information about the Users mailing list