Date: Tue, 4 Apr 2017 09:23:47 -0400 From: Mike Tancsa <mike@sentex.net> To: "Andrey V. Elsukov" <bu7cher@yandex.ru>, FreeBSD-STABLE Mailing List <freebsd-stable@freebsd.org>, svn-src-stable-11@freebsd.org Subject: Re: svn commit: r315514 - in stable/11: . contrib/netcat lib/libipsec sbin/ifconfig sbin/ipfw sbin/setkey share/man/man4 sys/conf sys/libkern sys/modules sys/modules/ipsec sys/modules/tcp/tcpmd5 sys/ne... Message-ID: <6f65e093-cbcb-ff02-3e62-a0aac0c7f303@sentex.net> In-Reply-To: <2aa232b9-df57-3512-ae98-1d4b03bb00d4@yandex.ru> References: <201703182204.v2IM4Kfj060263@repo.freebsd.org> <7738349f-e89a-d37d-e36f-0a5e18dc4249@sentex.net> <cdff758c-e7d7-d22d-512e-2137ba70e78a@yandex.ru> <a3ee1736-ca0b-76dc-0561-6bd27dd79071@sentex.net> <2aa232b9-df57-3512-ae98-1d4b03bb00d4@yandex.ru>
next in thread | previous in thread | raw e-mail | index | archive | help
On 4/4/2017 7:18 AM, Andrey V. Elsukov wrote: > On 04.04.2017 13:55, Mike Tancsa wrote: >>> You have many SAs with the same destination address, it seems to me, >>> that this should not work with old IPsec code, because it uses SA >>> lookups using only destination address. So, if you have not the same >>> password for each SA, it should not work. >>> >>> Can you try the attached patch? Thanks, the patch works! I am able to load all 42 rules now. I am going to test them in the lab against a few VMs prior to deployment. ---Mike -- ------------------- Mike Tancsa, tel +1 519 651 3400 Sentex Communications, mike@sentex.net Providing Internet services since 1994 www.sentex.net Cambridge, Ontario Canada http://www.tancsa.com/
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?6f65e093-cbcb-ff02-3e62-a0aac0c7f303>