[strongSwan] 答复: About the problem of re ceived netlink error: Resource temporar ily unavailable

2009-09-17 Thread weiping deng
Hi Martin, My kernel version is: 2.6.28 and I have patched with the patch you gave me before, and I also got the following error messages: kernel_netlink_shared.c:241:Resource temporarily unavailable-93: received netlink error kernel_netlink_ipsec.c:1162:c3fddd90: unable to add SAD entry with

Re: [strongSwan] Working with Different SAs with same src-dst IP but different Port

2009-09-17 Thread vivek bairathi
Hi, We are in a very critical state of our project. Please fin gtime to respond to the issue below. I would be of great help to us Thanks in advance, Ritu On 9/16/09, vivek bairathi bairathi.vi...@gmail.com wrote: Hi, We have the requirement that traffic between same source-destination IPs

[strongSwan] _updown is not called

2009-09-17 Thread Zhang, Long (Roger)
Hi, I am using preshared key instead of certificate to setup an IPSec tunnel. After the tunnel is setup successfully, I found the _updown script is not called. Using the test case http://www.strongswan.org/uml/testresults43/ikev2/virtual-ip-override/, the _updown can be called. Since I want

Re: [strongSwan] _updown is not called

2009-09-17 Thread Andreas Steffen
Hello Roger, the IKEv2 charon daemon configures virtual IPs directly using the RT_NETLINK kernel interface whereas the IKEv1 pluto daemon does in fact uses the _updown script to install virtual IP addresses. With the IKEv2 you can use either the standard leftfirewall=yes which calls the

Re: [strongSwan] a particular ``no trusted third party'' setup with X.509

2009-09-17 Thread Ivan Shmakov
Dimitrios Siganos dimitris... writes: [...] * when there're no trusted third party to serve as the CA to sign the certificates for the hosts belonging to the sites, each of the sites should sign the certificates used by the hosts of the other site to connect to the hosts of this site