Re: SNAT before IPSec

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 06/06/07 10:39, Jorge Davila wrote:
to be honest, reading, re-reading before the rfc the same doubt come to my mind but now, my understanding is that the paragraph is really doing reference to an interface to manage the traffic according to the policies defined.

*nod*

I think the reason that network interfaces stopped being created was in preparation for MANY IPSec connections, enough so that creating network interfaces would just be a waste. If I recall correctly the IPSec people were wanting and hoping to start seeing IPSec used arbitrarily any time that it could be used, including accessing web pages off of web servers. In this case, creating and removing interfaces is just (IMHO) ridiculing.



Grant. . . .


[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux