Re: xfrm selector generating IKE
From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2009-02-25 02:27:55
From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2009-02-25 02:27:55
On Tue, Feb 24, 2009 at 06:07:06PM -0800, Paul Moore wrote:
You seem to be saying that that if I explicitly set the policy reqids that it should work. I had experimented with that a lot The problem is that I cannot find a good combination of reqids
It's very simple, you want each equivalent class of SAs (i.e., SAs where any one can replace the other) to be assigned a unique reqid. The Openswan algorithm simply assigns an ID to each policy (or connection as it stores them internally), and then uses that ID as the reqid. Cheers, -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} [off-list ref] Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt