Re: [strongSwan] unable to add pseudo IPIP SA with SPI c1bb6ffe: Invalid argument

2011-11-20 Thread Lupe Christoph
On Monday, 2011-11-14 at 14:39:39 +0100, Tobias Brunner wrote: strongswan4-mod-kernel-klips - 4.5.2-1 Please try to remove this module from your build. The kernel-klips plugin was done for a very specific (and rather old) KLIPS release. And depending on whether your kernel actually

Re: [strongSwan] unable to add pseudo IPIP SA with SPI c1bb6ffe: Invalid argument

2011-11-20 Thread Andreas Steffen
Hello Christoph, it is up to you which IPsec package to use. In our opinion the IPsec policy rules offered by Linux netfilter are powerful enough to bind plaintext traffic coming out or going into an IPsec tunnel to any specific firewall rules. Of course a special interface would be nice but this

Re: [strongSwan] unable to add pseudo IPIP SA with SPI c1bb6ffe: Invalid argument

2011-11-14 Thread Tobias Brunner
Hi, strongswan4-mod-kernel-klips - 4.5.2-1 Please try to remove this module from your build. The kernel-klips plugin was done for a very specific (and rather old) KLIPS release. And depending on whether your kernel actually includes the KLIPS patch or not might never work. So, do you

[strongSwan] unable to add pseudo IPIP SA with SPI c1bb6ffe: Invalid argument

2011-11-13 Thread Lupe Christoph
Hi! I was forced by a buggy openswan port to try StrongSwan on OpenWRT Backfire 10.03.01 RC6 (pluto did not receive reply packets, if you care). The server is still using OpenSwan. But even after a lot of fiddling with settings I can't get StrongSwan to connect. Here is the info that hopefully