[strongSwan] What is the difference between libipsec and kernel_libipsec?

Dan Cook onedsc at gmail.com
Thu Jul 9 02:47:39 CEST 2015


I am experiencing an issue with SLES SP3 when trying to establish a
connection.

We are using PSK for I see the establishment of the IKE_SA in the log, but
immediately after that I see:

2015-07-08T20:44:38+0000 10[KNL] received netlink error: Function not
implemented (38)
2015-07-08T20:44:38+0000 10[KNL] unable to add SAD entry with SPI ca4e7100
2015-07-08T20:44:38+0000 10[KNL] received netlink error: Function not
implemented (38)
2015-07-08T20:44:38+0000 10[KNL] unable to add SAD entry with SPI ca2a94a2
2015-07-08T20:44:38+0000 10[IKE] unable to install inbound and outbound
IPsec SA (SAD) in kernel

After doing some research it looks like I need to use the libipsec plugin.
Is that correct?

I see two configuration options:  --enable-kernel-libipsec and the
--enable-libipsec.

What's the difference and are they configured differently?

Dan
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20150708/413b6254/attachment.html>


More information about the Users mailing list