Page 1 of 1

Make Strongswan start on a b3

Posted: 06 Oct 2011, 15:41
by kurt2000

I'm really disappointed to see that excito still not have included 2 small modules in your kernel-module packages.

Every time there is a new kernel i have to grab the source and compile the modules.

What a waste.

please take a look : ... rt_on_a_b3


Re: Make Strongswan start on a b3

Posted: 08 Oct 2011, 05:33
by Joric17
Yes, idem for Ecryptfs!

See also: ... _on_the_B3



Re: Make Strongswan start on a b3

Posted: 12 Oct 2011, 06:56
by kurt2000

I would like to hear if there is any reason why not to include theese 3 modules.

The funny thing is that they have enabled ipsec in the kernel. But not the 2 required modules.


Re: Make Strongswan start on a b3

Posted: 16 Oct 2011, 15:02
by johannes
Afik there is no reason that we didn't include them other than that it has been forgotten. It's now in our bug tracker and will be included in 2.4 if it doesn't cause any conflicts or other problems (together with nfs4 and iotop).

Re: Make Strongswan start on a b3

Posted: 19 Oct 2011, 06:27
by Gordon
FWIW I found the Netkey stack too unstable anyway and turned to Klips, which I also find easier to manage because it adds an ipsec0 interface. Yes you still need the kernel source, but since building the Klips module doesn't require to build all the other kernel related stuff as well you're done a lot quicker.

And there's a bonus: using iproute2 I can set the IP from br0 as the source address on traffic that should pass through the ipsec0 interface. This tiny tweak allows me to also access resources, such as the Samba shares, on the B3. AFAIK there's no way to accomplish this with Netkey.