RE: linux-ipsec: Latest IPsec and connecting two IP networks.... :-( > Is there any reason why the Aug30 IPsec would be "crashing" the
Nope, that's a new one on us.
>I found the bug mentioned below BTW. :-)
It turns out that the AH+ESP bug is a real weirdie: it looks like if you
have full logging (Klips and Pluto) turned on, on an old slow machine,
*and* you're running both AH and ESP, the volume of logging congests the
kernel so badly that (a) kernel logging just chokes and dies, and (b)
network packets get lost. We haven't fully investigated it yet, but it
doesn't seem to be specifically an IPSEC bug; apparently the combination
of AH and ESP just bloats the logging to the point of pushing it over the
edge. With the logs turned off, it works.
Henry Spencer
henry@spsystems.net
(henry@zoo.toronto.edu)
Received on Tue Sep 1 23:23:37 1998
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 12:59:26 EDT
|