Is it correct that for an inbound policy to be completely effective, it needs to be added to both the XFRM_POLICY_IN table as well as the XFRM_POLICY_FWD table? I'm asking because it seems that neither racoon nor isakmpd adds anything to the forward table. Or did I miss them? Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <herbert@gondor.apana.org.au> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt - : send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html