On 11/25/2012 05:27 PM, ip flow wrote: > Thanks Tobias! > I have two more questions on compliance: > > 1. Does StrongSwan support RFC 2405 - The ESP DES-CBC Cipher > Algorithm With Explicit IV Yes, implemented for ESP by the Linux kernel, configurable by strongSwan
> 2. Do you know if NETKEY support RFC 4301, Section 5.1.1 - Handling an > Outbound Packet That Must Be Discarded: If an IPsec system receives an > outbound packet that it finds it must discard, it SHOULD be capable of > generating and sending an ICMP message to indicate to the sender of > the outbound packet that the packet was discarded. > I'm not aware that NETKEY is sending an ICMP message to the sender if it DISCARDS a packet. > Regds > Regards Andreas ====================================================================== Andreas Steffen [email protected] strongSwan - the Linux VPN Solution! www.strongswan.org Institute for Internet Technologies and Applications University of Applied Sciences Rapperswil CH-8640 Rapperswil (Switzerland) ===========================================================[ITA-HSR]== _______________________________________________ Users mailing list [email protected] https://lists.strongswan.org/mailman/listinfo/users
