Re: port-based filtering of ESP packets with in-kernel IPsec?

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Wed, 30 Jul 2003, Chris Wilson wrote:

> Logically, it makes sense to me that the packet should pass through the 
> whole of Netfilter _again_ after it's been decapsulated, similarly to what 
> now happens with FreeS/WAN (but presumably without an ipsec0 interface 
> being involved). Or, maybe it should be decapsulated before routing (and 
> hence visible unencrypted in FORWARD, INPUT and OUTPUT).

It needs to pass routing first unless something has changed drastically 
in the 2.6 IP networking code, or else the kernel won't know if the 
ipsec packet is to be decapsulated or routed.

Regards
Henrik



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux