[LARTC] U32 filter for IPSEC (ESP)

Linux Advanced Routing and Traffic Control

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Mon, Jan 06, 2003 at 12:49:54AM +0100, Gilles Douillet wrote:

> so this u32 filter should work ? (I can use fw filter because the
> firewall/VPN can't mark pakets :-(
> 
> tc filter add dev ethX parent X:0 protocol ip prio X u32 match ip protocol
> 50 0xff flowid X:XX ?

Looks fine, but try proving it - just send this traffic to anotherwise empty
class and run 'tc -s qdisc ls dev eth0' and 'tc -s class ls dev eth0' to see
if the counters change.

Regards,

bert

-- 
http://www.PowerDNS.com      Open source, database driven DNS Software 
http://lartc.org           Linux Advanced Routing & Traffic Control HOWTO
http://netherlabs.nl                         Consulting


[Index of Archives]     [LARTC Home Page]     [Netfilter]     [Netfilter Development]     [Network Development]     [Bugtraq]     [GCC Help]     [Yosemite News]     [Linux Kernel]     [Fedora Users]
  Powered by Linux