Re: port based filtering and IPsec 2.6

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Sun, Jan 18, 2004 at 09:34:21AM +0000, Antony Stone wrote:
> On Sunday 18 January 2004 9:14 am, Marc Haber wrote:
> > I hope that I made my point clear.
> 
> Indeed, thanks.   I understand now why you dislike it.
> 
> I guess I've just been lucky that I prefer compiling my own kernels
> anyway, I don't mind a strange patching mechanism so long as it
> works, and I've not joined the mailing list because I've found the
> info I need in the documentation or in the list archives.

I compile my own kernels as well, but I package them for easier
distribution to the productive machines. And I like to have .diff
files that can easily be reproduced by my colleagues.

> I agree with the point made earlier however that it's a very poor
> situation if the 2.6 kernel IPsec won't allow filtering unencrypted
> packets.

Yes. It that's really impossible, it's a killer for kernel 2.6 ipsec
in my environment.

Greetings
Marc

-- 
-----------------------------------------------------------------------------
Marc Haber         | "I don't trust Computers. They | Mailadresse im Header
Karlsruhe, Germany |  lose things."    Winona Ryder | Fon: *49 721 966 32 15
Nordisch by Nature |  How to make an American Quilt | Fax: *49 721 966 31 29


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux