Thread (31 messages) 31 messages, 4 authors, 2009-02-25

Re: xfrm selector generating IKE

From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2009-02-25 02:38:14

On Tue, Feb 24, 2009 at 06:30:41PM -0800, Paul Moore wrote:
could u suggest a numbering for my 4 rules - as I said , no combination
I have tried works

// for outbound connections
subnet -> subnet[21] out
subnet[21] -> subnet in
// for inbound connections
subnet[21] -> subnet out
subnet -> subnet[21] in
If you want them to each use distinct SAs, then 1/2/3/4 or any
four distinct reqid's will do.  The point is that you should set
the reqid on the policy yourself instead of having the kernel pick
one for you at random.  Then you know what to assign to your SAs
when you create those.

Cheers,
-- 
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} [off-list ref]
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help