[strongSwan] Issues with kernel-libipsec and \32

Martin Willi martin at strongswan.org
Fri Oct 25 18:00:56 CEST 2013


Hi Tobias,

> I am working on a research project where we compare performances of a VPN
> connection with ipsec in kernel space with ipsec in user space.

Just FYI: Such a comparison with kernel-libipsec is probably not that
meaningful; our libipsec backend is relatively new and didn't yet get
any performance optimizations. This might have some impact, especially
with many SAs.

> [wiki.strongswan.org/issues/380] seems to fix that problem. However we
> still have the same error. We would like to be sure version 5.1.0  got
> patched.

No, these patches are not part of 5.1.0. Try 5.1.1rc1 [1], it should
contain all the changes.

> Attached find my configuration files and the charon log.

Seems that they are missing. Anyway, also check that you set the
appropriate mark options, as seen in the merge commit at [2].

Regards
Martin

[1]http://download.strongswan.org/strongswan-5.1.1rc1.tar.bz2
[2]http://git.strongswan.org/?p=strongswan.git;a=commit;h=1ff63f15





More information about the Users mailing list