Received: with ECARTIS (v1.0.0; list netdev); Sun, 27 Mar 2005 02:07:11 -0800 (PST) Received: from arnor.apana.org.au (mail@arnor.apana.org.au [203.14.152.115]) by oss.sgi.com (8.13.0/8.13.0) with ESMTP id j2RA731S018353 for ; Sun, 27 Mar 2005 02:07:04 -0800 Received: from gondolin.me.apana.org.au ([192.168.0.6] ident=mail) by arnor.apana.org.au with esmtp (Exim 3.35 #1 (Debian)) id 1DFUfE-00038b-00; Sun, 27 Mar 2005 20:06:36 +1000 Received: from herbert by gondolin.me.apana.org.au with local (Exim 3.36 #1 (Debian)) id 1DFUeO-0001IS-00; Sun, 27 Mar 2005 20:05:44 +1000 From: Herbert Xu To: pb@bieringer.de (Peter Bieringer) Subject: Re: IPv4 tunneled over IPv6-IPsec? Cc: dev@openswan.org, netdev@oss.sgi.com Organization: Core In-Reply-To: X-Newsgroups: apana.lists.net.openswan.dev,apana.lists.os.linux.netdev User-Agent: tin/1.7.4-20040225 ("Benbecula") (UNIX) (Linux/2.4.27-hx-1-686-smp (i686)) Message-Id: Date: Sun, 27 Mar 2005 20:05:44 +1000 X-Virus-Scanned: ClamAV 0.83/789/Fri Mar 25 21:33:13 2005 on oss.sgi.com X-Virus-Status: Clean X-archive-position: 781 X-ecartis-version: Ecartis v1.0.0 Sender: netdev-bounce@oss.sgi.com Errors-to: netdev-bounce@oss.sgi.com X-original-sender: herbert@gondor.apana.org.au Precedence: bulk X-list: netdev Content-Length: 656 Lines: 17 Peter Bieringer wrote: > > I retry to play tunneling IPv4 over IPv6-IPsec. Afair it is still not > working (support is missing in 2.6.x kernel), but for startup, I have > already a patch for ipsec.conf parsing (pluto already has an option to do > this): The native IPsec stack doesn't support IPv4 over IPv6 or IPv6 over IPv4 SAs. It won't be able to do so unless major surgery is done to the IPsec and IP stack. Cheers, -- Visit Openswan at http://www.openswan.org/ Email: Herbert Xu ~{PmV>HI~} Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt