From mboxrd@z Thu Jan 1 00:00:00 1970 From: Carl-Daniel Hailfinger Subject: Re: New extension: CRYPT target Date: Sun, 21 May 2006 19:01:48 +0200 Message-ID: <44709CFC.7050007@gmx.net> References: <44708E68.9080508@speedy.com.ar> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Cc: netfilter-devel@lists.netfilter.org Return-path: To: Gervasio Bernal In-Reply-To: <44708E68.9080508@speedy.com.ar> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-devel-bounces@lists.netfilter.org Errors-To: netfilter-devel-bounces@lists.netfilter.org List-Id: netfilter-devel.vger.kernel.org Gervasio Bernal wrote: > (on host A, 1.2.3.4, FTP client) > # iptables -t mangle -A POSTROUTING -d 1.2.3.5 -p tcp --dport 20:21 -j > CRYPT --cipher blowfish --key topsecret --mode ecb --direction encrypt Ouch. If anybody runs ps while this iptables command is running, he has your top secret key. Does this provide any benefit over IPSEC? Regards, Carl-Daniel -- http://www.hailfinger.org/