This bug still applies to the current OpenVZ kernel in Debian Squeeze. I'm greatly surprised that OpenVZ by default blocks using IPsec in *hardware nodes*, which is an industry (and IETF) standard VPN solution for IPv4 and (mandatorily) for IPv6.