Hello, Is there any way to create an IPsec tunnel and indicate using extended sequnce numbers? It seems that currently iproute2 doesn't support this. Grepping for "esn" reveals that XFRM_STATE_ESN shows only in kernel headers. The only relevant thing I found was a RFC sent by Steffen (Cc-ed), but it was never applied (don't know why): [RFC] iproute2: Add IPsec extended sequence number support http://patchwork.ozlabs.org/patch/85962/ Thank you, Horia -- To unsubscribe from this list: send the line "unsubscribe linux-crypto" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html