Re: Rationale for policy check procedure

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sun, Jun 29, 2003 at 02:27:22PM -0700, David S. Miller wrote:
>    From: Herbert Xu <herbert@gondor.apana.org.au>
>    Date: Mon, 30 Jun 2003 07:28:07 +1000
>    
>    However, it does make it more complex in that a new connection
>    could cause all existing policy templates to change.
> 
> Connections do not change policies, policy changes change policies.
> 
> Connections match policies and expand templates to create specific
> transformer states which are applied to packets from that connection.

That sounds good but the bottom line is that the KM has to update each
policy in this case to expand the templates, right?
-- 
Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ )
Email:  Herbert Xu ~{PmV>HI~} <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
-
: send the line "unsubscribe linux-net" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Netdev]     [Ethernet Bridging]     [Linux 802.1Q VLAN]     [Linux Wireless]     [Kernel Newbies]     [Security]     [Linux for Hams]     [Netfilter]     [Git]     [Bugtraq]     [Yosemite News and Information]     [MIPS Linux]     [ARM Linux]     [Linux RAID]     [Linux PCI]     [Linux Admin]     [Samba]

  Powered by Linux