On 09/18/2014 11:28 AM, Tony Zhou wrote:
> However I think on OpenVZ, strongswan is unable to forward ipsec
> traffic to proper interface, which I believe it is an upstream
> problem: https://wiki.strongswan.org/issues/592
This is getting off-topic but I only ever tried to run IPsec in the HW
node context and protect traffic for the VEs. This required disabling
this in the *VE*: sysctl net.ipv4.conf.venet0.disable_policy=1
Hi Tony
On 09/18/2014 11:28 AM, Tony Zhou wrote: /wiki.strongswa n.org/issues/ 592
> However I think on OpenVZ, strongswan is unable to forward ipsec
> traffic to proper interface, which I believe it is an upstream
> problem: https:/
This is getting off-topic but I only ever tried to run IPsec in the HW conf.venet0. disable_ policy= 1
node context and protect traffic for the VEs. This required disabling
this in the *VE*: sysctl net.ipv4.
HTH,
Simon