El vie, 28-10-2005 a las 06:07 -0600, Jorge I. Davila L. escribió: > Why don't try: > > kernel 2.6.12 > iptables 1.3.3 > > After that, see If you still needs the patches (from patch-o-matic and > from shorewall.net) Jorge: Thanks for your reply. I am working with 2.6.12, and it doesn't have the needed "policy match extension" patch. I don't think iptables 1.3.3 has the ipsec hooks and policy patches, since they're still in "testing" over at netfilter.org. Incidentally, I think the folks at netfilter should pay more attention to the difficulties with ipsec and iron them out. -- Oscar A. Valdez