Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-11-02 Thread Herbert Xu
Evan Gilman wrote: > > I tried to find a reference to the previous report of aesni-intel > causing IPSec corruption under Xen - I'd be interested to read it if > anyone here has it on hand. For now, we are looking to blacklist > aesni-intel as we have no other suitable solution, and when combined

Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-10-30 Thread Evan Gilman
Indeed, I am using aesni-intel. I have again been bitten by this problem, but do not have the cycles to pinpoint the kernel version in which the trouble was introduced. I have done a bit more research, and have found that hosts running under Xen 4.4.2 are not affected (regardless of kernel version)

Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-06-30 Thread Herbert Xu
On Mon, Jun 30, 2014 at 01:33:24PM +0200, Steffen Klassert wrote: > Ccing netdev. > > On Thu, Jun 26, 2014 at 02:12:30PM -0700, Evan Gilman wrote: > >Hi all > >We have a couple Ubuntu 10.04 hosts with kernel version 3.14.5 which are > >experiencing TCP payload corruption when using IPS

Re: Sporadic ESP payload corruption when using IPSec in NAT-T Transport Mode

2014-06-30 Thread Steffen Klassert
Ccing netdev. On Thu, Jun 26, 2014 at 02:12:30PM -0700, Evan Gilman wrote: >Hi all >We have a couple Ubuntu 10.04 hosts with kernel version 3.14.5 which are >experiencing TCP payload corruption when using IPSec in NAT-T transport >mode. All are running under Xen at third party prov