Re: tcpdumping ipsec encrypted/decrypted packets

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Patrick McHardy wrote:

Marco Berizzi wrote:
Browsing the linux-net archive, I have seen that 2.6.16
will contain all ipsec hooks patches from Patrick McHardy.
Also there will be an iptables policy match to match the
ipsec policy. This patch will permit more granular control
than KLIPS ipsec virtual devices (ipsecX).
Question: will be there a way to tcpdump all traffic going
to be encrypted/decrypted? Actually with KLIPS this is
easy: tcpdump -i ipsec0

I have an unfinished patch to do this, I'll post it for discussion
after the remaining netfilter/IPsec issues are settled. One thing
I'm not sure about yet is how to tell tcpdump not to show these
packets, or to only show these packets. One possibility would be
to add new qualifiers ("ipsec"/"not ipsec" or something like that),
similar to the inbound/outbound qualifiers for ppp devices. Another
(IMO more ugly) way would be to use a dummy device.

Ciao Patrick,

any news?

TIA


-
To unsubscribe from this list: send the line "unsubscribe linux-net" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html

[Index of Archives]     [Netdev]     [Ethernet Bridging]     [Linux 802.1Q VLAN]     [Linux Wireless]     [Kernel Newbies]     [Security]     [Linux for Hams]     [Netfilter]     [Git]     [Bugtraq]     [Yosemite News and Information]     [MIPS Linux]     [ARM Linux]     [Linux RAID]     [Linux PCI]     [Linux Admin]     [Samba]

  Powered by Linux