Re: [RFC, PATCH 3/5]: netfilter+ipsec - input hooks
From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2004-03-19 11:47:57
Also in:
netfilter-devel
From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2004-03-19 11:47:57
Also in:
netfilter-devel
On Thu, Mar 18, 2004 at 10:15:23PM -0800, David S. Miller wrote:
Be careful! xfrm4_tunnel handles both uncompressed ipcomp packets _and_ IPIP encapsulator device packets. Yet you will intepret usage of the ipprot as 'xfrm_prot==1' in all cases.
Good point.
Yes this is ugly... if we added some kind of flag bit-mask to sk_buff, would that allow an easier implementation?
I'm not sure if this'll help in the degenerate IPCOMP case. Perhaps we need a way to tell if it is a degenerate IPCOMP tunnel or an IPIP tunnel without actually processing the packet. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} [off-list ref] Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt