[LARTC] U32 filter for IPSEC (ESP)

Linux Advanced Routing and Traffic Control

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi all,

After reading a lot and searching on the INternet, I want to filter ASP
and/or AH traffic

According to /etc/protocols ESP and AH are IP protos 50 and 51

so this u32 filter should work ? (I can use fw filter because the
firewall/VPN can't mark pakets :-(

tc filter add dev ethX parent X:0 protocol ip prio X u32 match ip protocol
50 0xff flowid X:XX ?

Can someone confirm this ?

Many thanks

G.





[Index of Archives]     [LARTC Home Page]     [Netfilter]     [Netfilter Development]     [Network Development]     [Bugtraq]     [GCC Help]     [Yosemite News]     [Linux Kernel]     [Fedora Users]
  Powered by Linux