>I am tempted to "outsource" the IPsec functionality away from the
>kernel using a demon on a divert socket, just like NATD. This would
>be more modular and keeps the kernel from panicing because of bugs
>in IPsec -- I did have embarrassing kernel crashes, just when I bragged
>about FreeBSD running rock solid :0(.

        checking - did you have kernel panics in kernel IPsec code (then pls
        send-pr), or you are just talking about an example?

itojun

To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-net" in the body of the message

Reply via email to