>I am tempted to "outsource" the IPsec functionality away from the
>kernel using a demon on a divert socket, just like NATD. This would
>be more modular and keeps the kernel from panicing because of bugs
>in IPsec -- I did have embarrassing kernel crashes, just when I bragged
>about FreeBSD running rock solid :0(.

        checking - did you have kernel panics in kernel IPsec code (then pls
        send-pr), or you are just talking about an example?

itojun

---------------------------------------------------------------------
The IPv6 Users Mailing List
Unsubscribe by sending "unsubscribe users" to [EMAIL PROTECTED]

Reply via email to