VPNaaS: Fedora support for StrongSwan
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
neutron |
Fix Released
|
Undecided
|
Wei Hu |
Bug Description
In early testing, I was unable to create a VPN connection using Fedora Release 12 and StrongSwan driver.
Found out from StrongSwan IRC folks these issues:
A) Unlike Ubuntu, both Strongswan and LibreSwan can be installed at once
B) Fedora uses the process name "strongswan", whereas Ubuntu uses "ipsec". The "ipsec" process is for LIbreSwan, under Fedora.
C) The may be some sensitivity to tabs, in the config file, for Fedora (use only one?)
The StrongSwan folks also mentioned about a issue, where one needs a kernel with support for XFRM and namespaces. They stated that there can be problems with passing traffic. They indicated it was a kernel issue and therefore applied to all Swan flavors.
Research is needed to see if both Ubuntu and Fedora kernels have this support. Currently, we don't see an issue with Ubuntu, but should verify the kernel for all target operating systems.
Changed in neutron: | |
assignee: | nobody → venkata anil (anil-venkata) |
Changed in neutron: | |
assignee: | venkata anil (anil-venkata) → Wei Hu (huwei-xtu) |
status: | New → In Progress |
Changed in neutron: | |
milestone: | none → liberty-1 |
status: | Fix Committed → Fix Released |
Changed in neutron: | |
milestone: | liberty-1 → 7.0.0 |
Hi @venkata anil, I filed a bug for this issue today(my fault not to find this issue first), and committed a patch. Do you mind we co-work to fix this bug. /review. openstack. org/#/c/ 174205/
See bug 1444776.
https:/