Re: [TUN]: Clear security path for tunnel packets

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hello!

> IPIP still didn't work after my last fix.  It turns out that the security
> path is not cleared for packets inside the tunnel. This breaks when the
> SA selectors on the outside of the tunnel only allow packets with the
> same source/destination address.

... which actually most likely means that the check is wrong.
Is it due to the fact that you used tunnel addresses from SA to restore
addresses to apply selector and that this information is not available
for plain tunnel?


> This patch clears the security path for all tunnel packets.

Think more, please. I do not believe clearing the path is a good idea.
It is too easy to be right. :-)

Alexey
-
: send the line "unsubscribe linux-net" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Netdev]     [Ethernet Bridging]     [Linux 802.1Q VLAN]     [Linux Wireless]     [Kernel Newbies]     [Security]     [Linux for Hams]     [Netfilter]     [Git]     [Bugtraq]     [Yosemite News and Information]     [MIPS Linux]     [ARM Linux]     [Linux RAID]     [Linux PCI]     [Linux Admin]     [Samba]

  Powered by Linux