[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-Id: <20171218.125642.639075398593924537.davem@davemloft.net>
Date: Mon, 18 Dec 2017 12:56:42 -0500 (EST)
From: David Miller <davem@...emloft.net>
To: lorenzo@...gle.com
Cc: netdev@...r.kernel.org, steffen.klassert@...unet.com,
subashab@...eaurora.org, nharold@...gle.com
Subject: Re: [RFC ipsec-next 3/4] net: xfrm: support multiple VTI tunnels
From: Lorenzo Colitti <lorenzo@...gle.com>
Date: Tue, 19 Dec 2017 01:16:55 +0900
> - ICMP errors are similar to input, except the search is for the
> outbound XFRM state, because the only data that is available is
> the outbound SPI. Thus, ICMP errors are only processed if the
> ikey is the same as the same as the okey. AFAICS this is
> consistent with GRE tunnels, but not with existing VTI
> behaviour.
I think you will need to sort out the VTI ICMP behavior difference
with what exists now.
Powered by blists - more mailing lists