On Wed, Jan 21, 2004 at 04:37:48PM +0100, Valentijn Sessink wrote: > Yes you can. Re-read my post, and be creative. That will work for incoming packets. And how do I protect myself against configuration errors sending out unencrypted packets? I'd need to put the mark on the packets for destination networks, which is error prone. The idea is nice, but it looks like an ugly hack. And it _is_ an ugly hack. Greetings Marc -- ----------------------------------------------------------------------------- Marc Haber | "I don't trust Computers. They | Mailadresse im Header Karlsruhe, Germany | lose things." Winona Ryder | Fon: *49 721 966 32 15 Nordisch by Nature | How to make an American Quilt | Fax: *49 721 966 31 29