Hi, 1) upgrade to kernel 2.6.29 and apply patch  from above, to the linux kernel. No, 2.6.29 already contains the patch. 2) stick with kernel 2.6.28 and apply the disable-iaf-tunnels patch to charon, (this patch will brake v6/v4 mixed operation) Yes, then no kernel patch is required.
Martin Willi wrote: It seems that if I remove all of the Ipv6 modules the IPsec doesn't work Make sure to have at least a 2.6.29 kernel, apply the kernel patch  or use the workaround patch for strongSwan (attached, breaks mixed v4/v6 tunnels). Regards Martin
Hi, The webpage http://wiki.strongswan.org/wiki/1/KernelModules states that the following kernel modules are required for strongswan operation: Networking --- Networking options --- Transformation user configuration interface PF_KEY sockets TCP/IP networking IP: advanced