Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 11 May 2000 01:17:20 -0700 (PDT)
From:      Kris Kennaway <kris@FreeBSD.org>
To:        Matthew Dillon <dillon@apollo.backplane.com>
Cc:        Ville-Pertti Keinonen <will@iki.fi>, hackers@FreeBSD.ORG
Subject:   Re: ipsec 'replay' syslog error messages after reboot of one host
Message-ID:  <Pine.BSF.4.21.0005110112410.27069-100000@freefall.freebsd.org>
In-Reply-To: <200005110733.AAA62618@apollo.backplane.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, 11 May 2000, Matthew Dillon wrote:

>     I had to fix up /etc/rc.network a little to load the ipsec rules
>     at the appropriate point (just after the interface and ipfw setup,
>     but before any services (like NFS) are run).  I am going to put the
>     (relatively simple) patch for rc.network up for a quick review and
>     then commit it along with an example file and a reference to the
>     example file in the man page.

Please submit this to the KAME folks (snap-users@kame.net) as well so we
can keep in sync. I'm in the process of merging the latest KAME snapshot
into 5.0 with the aim of trying to update our IPv6/IPSec support
(Currently our IPSec code dates to November 1999), so keeping the two
codebases in sync as much as possible will help my job - I don't want the
FreeBSD IPv6/IPsec code to get ahead of the KAME code, or I'm likely to
miss the change locally and blow it away.

I'm not sure whether or not the problem you had was a bug - again, you'd
be best off speaking to the KAME guys directly (although given the age of
our ipsec code I don't know how much they'd be able to help)

Kris

----
In God we Trust -- all others must submit an X.509 certificate.
    -- Charles Forsythe <forsythe@alum.mit.edu>



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-hackers" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0005110112410.27069-100000>