Someone on the Strongswan mailing list [1] mentioned that 3.19 was also affected.
I quickly skimmed the changelog between 3.16.0-38-generic to 3.16.0-39-generic and a possible culprit could be: * ip_forward: Drop frames with attached skb->sk Clemens, would you be able to just revert the corresponding commit and see it if helps? 1: https://lists.strongswan.org/pipermail/users/2015-August/008644.html ** Changed in: linux (Ubuntu) Status: Expired => Incomplete -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1467561 Title: IPsec VTI functionality broken in 3.16.0-39 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1467561/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs