[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-ID: <alpine.LRH.2.00.0902101138380.21337@q7.q7.com>
Date: Tue, 10 Feb 2009 11:42:47 -0800 (PST)
From: Joe Pruett <joey@...an.q7.com>
To: netdev@...r.kernel.org
Subject: ipsec and netfilter
i've asked this on the netfilter list with no responses and there doesn't
seem to be an ipsec list for linux anymore, so maybe someone here will
have some insight...
why aren't esp/ah packets run through netfilter again after
decryption/decapsulation? in tunnel mode, packets do get sent in again,
but that is only because ip-ip does that, not the ipsec code.
i want to set up a host2host ipsec connection and be able to do standard
filtering on it, but the hooks just don't seem to be there. or am i
missing something?
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@...r.kernel.org
More majordomo info at http://vger.kernel.org/majordomo-info.html
Powered by blists - more mailing lists