[strongSwan] DSCP support in new version of strongswan

2010-10-15 Thread David Deng
Hi Andreas, Hi All, About the DSCP feature of strongswan, I want to know which patch has been applied for supporting this feature. please give me a link for the information about this patch. Thank you! Besides the code change of strongswan, if NETKEY need to be modified too? if so, can you

Re: [strongSwan] Interoperate with Juniper SSG 550M failed

2010-10-15 Thread David Deng
Hi Sajal, Hi Andreas, Hi Laurence, Hi All, Thank you for your useful document and kind help! Now we have established the IPsec tunnel between seGW(Juniper SSG550M) and Client, Thanks a lot! I think there are still a lot problem need your all help. thank in advance! Best wishes, David Morris

Re: [strongSwan] No known IPsec stacks found on Freebsd 8.1

2010-10-15 Thread Tobias Brunner
Yatong Cui wrote: Yet I cannot start the daemon because the system cannot identify any IPsec stack. That's not really a problem, the detection code is Linux specific and not actually executed by the daemon, but by a wrapper tool called starter. The daemon charon (with the proper plugin

Re: [strongSwan] DSCP support in new version of strongswan

2010-10-15 Thread Andreas Steffen
Hello, The DSCP feature using XFRM marks as shown in the scenario http://www.strongswan.org/uml/testresults44/ikev2/net2net-psk-dscp/ is supported by strongswan-4.4.1 or newer. The Linux 2.6.35 kernel or newer include the XFRM_MARK patch whereas the Linux 2.6.34 kernel must be patched with