Subject: Re: kern/30182: With FAST_IPSEC option, some IPSEC stats aren't
To: None <kern-bug-people@netbsd.org, gnats-admin@netbsd.org,>
From: Arto Selonen <arto@selonen.org>
List: netbsd-bugs
Date: 05/09/2005 19:33:02
The following reply was made to PR kern/30182; it has been noted by GNATS.

From: Arto Selonen <arto@selonen.org>
To: gnats-bugs@netbsd.org
Cc: kern-bug-people@netbsd.org, gnats-admin@netbsd.org,
	netbsd-bugs@netbsd.org
Subject: Re: kern/30182: With FAST_IPSEC option, some IPSEC stats aren't
	updated (setkey -D)
Date: Mon, 9 May 2005 22:31:53 +0300 (EEST)

 Hi!
 
 On Mon, 9 May 2005 groy@qnx.com wrote:
 
 >> Number:         30182
 >> Category:       kern
 >> Synopsis:       With FAST_IPSEC option, some IPSEC stats aren't updated (setkey -D)
 
 > It looks like some of the SA stats aren't being updated. When I configure transport mode encryption between two machines and ping between them, setkey -D will display my two SAs, but the stats for the outoing SA don't get updated (i.e. the bytes field and the allocated field never get incremented). They do get incremented for the incoming SA.
 >
 > This only occurs with the FAST_IPSEC option (it works OK when using IPSEC).
 
 This sounds like it might be related to bin/25796, although I don't 
 think I've ever used FAST_IPSEC. Also, I'm strictly with -current.
 
 
 Artsi
 -- 
 #######======------  http://www.selonen.org/arto/  --------========########
 Everstinkuja 5 B 35                               Don't mind doing it.
 FIN-02600 Espoo        arto@selonen.org         Don't mind not doing it.
 Finland              tel +358 50 560 4826     Don't know anything about it.