Re: [PATCH 2/2] [IPSEC]: Reinject v6 packet on input instead of calling netfilter
From: jamal <hidden>
Date: 2007-11-29 22:06:00
From: jamal <hidden>
Date: 2007-11-29 22:06:00
On Thu, 2007-29-11 at 22:21 +0100, Patrick McHardy wrote:
http://lists.openwall.net/netdev/2007/10/16/88quoted
I wouldnt mind just ipv4 going in - but that would be lacking consistency. Is there anything that can be done to get the extension headers to be processed only once?I would prefer to keep things consistent between IPv4 and IPv6.
Makes sense.
Not sure if anything could be done, perhaps we could keep the necessary parts of the IP6CB and skip parsing up to the ESP nexthdr.
I will compute in the background and talk to Yoshfuji (hopefully will bump into him next week;->). Herbert, if you have any clever ideas please shoot. cheers, jamal