Comment 8 for bug 1309594

Revision history for this message
Simon Déziel (sdeziel) wrote : Re: [Bug 1309594] Re: kernel-libipsec not loading

Hi Tony

On 09/18/2014 11:28 AM, Tony Zhou wrote:
> However I think on OpenVZ, strongswan is unable to forward ipsec
> traffic to proper interface, which I believe it is an upstream
> problem: https://wiki.strongswan.org/issues/592

This is getting off-topic but I only ever tried to run IPsec in the HW
node context and protect traffic for the VEs. This required disabling
this in the *VE*: sysctl net.ipv4.conf.venet0.disable_policy=1

HTH,
Simon