From mboxrd@z Thu Jan 1 00:00:00 1970 From: Patrick McHardy Subject: Re: New extension: CRYPT target Date: Fri, 26 May 2006 20:25:34 +0200 Message-ID: <4477481E.2070000@trash.net> References: <44708E68.9080508@speedy.com.ar> <20060525161148.GA2376@ecstasy.ring2.lan> <44774516.5020406@speedy.com.ar> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-15 Content-Transfer-Encoding: 7bit Cc: netfilter-devel@lists.netfilter.org Return-path: To: Gervasio Bernal In-Reply-To: <44774516.5020406@speedy.com.ar> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-devel-bounces@lists.netfilter.org Errors-To: netfilter-devel-bounces@lists.netfilter.org List-Id: netfilter-devel.vger.kernel.org Gervasio Bernal wrote: > I think the idea of encryption using Iptables is really great! The thing I don't get: what advantages does it have over using IPsec with manual keying (forgetting about the selector, once nfmark is supported this point won't matter)?