[Openswan Users] openswan start up a static Ipsec SAs

MichaelLeung gbcbooksmj at gmail.com
Fri Aug 14 02:23:28 EDT 2015


Hi all

does any one try to config a static Ipsec SAs before ?
-------------------------
i read man page of Ipsec.conf and saw these lines

    CONN PARAMETERS: MANUAL KEYING
        This command was obsoleted around the same time that Al Gore 
invented the internet. ipsec manual was used in the jurassic period to 
load static keys into the kernel. There are no
        rational reasons to use this, and it is not supported anymore. 
If you need to create static SAs, then you can use ipsec spi and ipsec 
eroute when using KLIPS or ip xfrm or setkey
        when using NETKEY.

-----------------------------

i dont quite know how to idenfind SPI session key .

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.openswan.org/pipermail/users/attachments/20150814/e47b2132/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: gbcbooksmj.vcf
Type: text/x-vcard
Size: 4 bytes
Desc: not available
URL: <http://lists.openswan.org/pipermail/users/attachments/20150814/e47b2132/attachment.vcf>


More information about the Users mailing list