[Swan] SA-replayed-pkt

Ted Toth txtoth at gmail.com
Mon Nov 26 22:59:20 UTC 2018


On a RHEL7 system running selinux-policy-mls and labeled ipsec I'm
seeing a lot of MAC_IPSEC_EVENT messages in the audit log with
op=SA-replayed-pkt. These look worrying to me but I have been able to
find out much about what they are actually telling me can anyone help
me out? Should I be worried?

Ted


More information about the Swan mailing list