looks good so far :-) i think the kernel-libipsec plugin should not be loaded by default
the plugin works only with UDP encapsulated packets (look here: https://wiki.strongswan.org/projects/strongswan/wiki/Kernel- libipsec) and this will break most of the "normal"/LAN setups i would build and include the plugin but disable the loading with /etc/strongswan.d/charon/kernel-libipsec.conf > load = no -- You received this bug notification because you are a member of Ubuntu Server Team, which is subscribed to strongswan in Ubuntu. https://bugs.launchpad.net/bugs/1535951 Title: Please merge strongswan 5.3.5-1 (main) from Debian unstable (main) To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/strongswan/+bug/1535951/+subscriptions -- Ubuntu-server-bugs mailing list Ubuntu-server-bugs@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-server-bugs