Date: Thu, 11 May 2000 01:17:20 -0700 (PDT) From: Kris Kennaway <kris@FreeBSD.org> To: Matthew Dillon <dillon@apollo.backplane.com> Cc: Ville-Pertti Keinonen <will@iki.fi>, hackers@FreeBSD.ORG Subject: Re: ipsec 'replay' syslog error messages after reboot of one host Message-ID: <Pine.BSF.4.21.0005110112410.27069-100000@freefall.freebsd.org> In-Reply-To: <200005110733.AAA62618@apollo.backplane.com>
next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, 11 May 2000, Matthew Dillon wrote: > I had to fix up /etc/rc.network a little to load the ipsec rules > at the appropriate point (just after the interface and ipfw setup, > but before any services (like NFS) are run). I am going to put the > (relatively simple) patch for rc.network up for a quick review and > then commit it along with an example file and a reference to the > example file in the man page. Please submit this to the KAME folks (snap-users@kame.net) as well so we can keep in sync. I'm in the process of merging the latest KAME snapshot into 5.0 with the aim of trying to update our IPv6/IPSec support (Currently our IPSec code dates to November 1999), so keeping the two codebases in sync as much as possible will help my job - I don't want the FreeBSD IPv6/IPsec code to get ahead of the KAME code, or I'm likely to miss the change locally and blow it away. I'm not sure whether or not the problem you had was a bug - again, you'd be best off speaking to the KAME guys directly (although given the age of our ipsec code I don't know how much they'd be able to help) Kris ---- In God we Trust -- all others must submit an X.509 certificate. -- Charles Forsythe <forsythe@alum.mit.edu> To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-hackers" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.21.0005110112410.27069-100000>