Hello Wolfgang, > We solved the problem by marking ipsec traffic in the mangle table > (PREROUTING). This mark is preserved when the packet gets decrypted. So > basically: > > * if a paket is AH, ESP mark it with 1 in mangle table, PREROUTING chain > > * if you see non-ip-sec pakets: if it is marked with 1 it is a decrypted ipsec > packet, otherwise it came in unencrypted. Many many thanks for this hint. I was searching the web so long for an acceptable solution for this problem. I have just tried out your solution and it works great. Once again thank you. > > Greetings, > > -- > Wolfgang Walter > Studentenwerk München > Anstalt des öffentlichen Rechts > - > : send the line "unsubscribe linux-net" in > the body of a message to majordomo@vger.kernel.org > More majordomo info at http://vger.kernel.org/majordomo-info.html -- bye Gregor ----------------------------- gpa@silete:~$ apt-get moo (__) (oo) /------\/ / | || * /\---/\ ~~ ~~ ...."Have you mooed today?"... - : send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html