Now it seems ok after inserting protostack parameter. I only have two more questions: 1) previously I inserted protostack but, without indentation, service gave me an error; why don't eliminate the need of indentation? 2) how to link ipsec0 to eth1 permanently (instead of eth0)? ipsec tncfg is not permanent... 3) there is no more /etc/init.d/ipsec start|stop|restart... right?
Antonio -----Messaggio originale----- Da: Paul Wouters [mailto:[email protected]] Inviato: domenica 15 marzo 2015 23.30 A: Antonio Scattolini Cc: [email protected] Oggetto: Re: [Swan] Installing klips On Sun, 15 Mar 2015, Antonio Scattolini wrote: > I tried to install libreswan with klips support using what is written in the > makefile or in the readme and readme.klips: Note libreswan always has klips support built in. I guess you mean to say you want to build and use klips? > make module module_install programs install > I did it after an "export KERNELSRC=/usr/src/linux" where linux is a link to > /usr/src/linux-source-3.16 obtained after extraction of > linux-source-3.16.tar.xz plus some make oldconfig && make prepare (in > /usr/src/linux) plus some other make I did (in /usr/src/linux) to correct > errors of make module module_install (in libreswan directory). looks good. > However I obtain: > root@fw:~# ipsec verify > Verifying installed system and configuration files > > Version check and ipsec on-path [OK] > Libreswan 3.12 (netkey) on 3.16.0-4-686-pae You did not change /etc/ipsec.conf to have protostack=klips ? Paul _______________________________________________ Swan mailing list [email protected] https://lists.libreswan.org/mailman/listinfo/swan
