Wolfgang Walter wrote:
Yes, it would be good if netfilter would be enhanced so that there is a native check for "came in as ipsec".
ipsec has already been integrated in the netfilter framework, the patches are available in patch-o-matic-ng, after some testing they will be merged to kernel stable branch.
regards, Pablo - : send the line "unsubscribe linux-net" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html