Replying to Lincoln Dale:
the logic is correct, but it may make sense to call the appropriate
netfilter hook again with the "unwrapped" GRE packet, as otherwise
packets-inside-GRE represent a possible security hole where one can inject
packets externally and bypass firewall rules.
From what I observe, netfilter hooks *are* called for unwrapped packets.
Either for usual IP packets passed from GRE tunnel, or for demangled
wccp packets.
--
Paul P 'Stingray' Komkoff Jr // http://stingr.net/key <- my pgp key
This message represents the official view of the voices in my head