On Sun, Feb 15, 2004 at 12:54:26AM +0100, Tobias Roth wrote: > yes, setkey -D never outputs anything, no SAs get created at all. This would tend to suggest either IPSEC support is missing from the kernel, or there has been a problem when racoon is issuing PF_KEY socket writes. Can you recompile with IPSEC_DEBUG enabled and try to replicate the problem? BMS