Re: SNAT before IPSEC - why?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sunday 2011-10-09 03:12, Stephen Clark wrote:

>>> http://jengelh.medozas.de/images/nf-packet-flow.png or .svg
>> Beautiful! Thanks,
>
>In looking at the graph - do in ipsec packets and out ipsec packet
>hit the INPUT and OUTPUT chains even if the packet is being
>forwarded and is not really destined for the machine running
>iptables?

It always depends on the routing table.
--
To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html


[Index of Archives]     [Netfitler Users]     [LARTC]     [Bugtraq]     [Yosemite Forum]

  Powered by Linux