Could someone clarify what exactly the warning message in the subject (from ip6tables) is supposed to tell me? It looks like that ip6tables -p ah (or -p in general) would match packets that contain an ah header as the last extension header whereas -m ah matches packets that contain an ah header at any position, but I'm not sure. The core of the question is this: how does one pass unspecified ipsec traffic in ip6tables (the way you could do with -p ah + -p esp in iptables)? Thanks & Regards, Thomas
Attachment:
signature.asc
Description: This is a digitally signed message part