iptables rules to match ESP packets work fine for raw ESP, but they do
not work for ESP over UDP packets.
Looking into the code, it seems that netfilter hooks are not invoked for
ESP packets that came over UDP.
Does somebody already have a patch to resolve this issue?
Thanks,
Shekhar