All of lore.kernel.org
 help / color / mirror / Atom feed
* SNAT before IPSEC - why?
@ 2011-10-08  2:08 Stephen Clark
  2011-10-08  8:06 ` Chris Wilson
                   ` (2 more replies)
  0 siblings, 3 replies; 10+ messages in thread
From: Stephen Clark @ 2011-10-08  2:08 UTC (permalink / raw)
  To: Netfilter Developer Mailing List

Hi,

What is the reasoning for having SNAT happen before ipsec encryption?

It forces one to add special rules in the NAT table to keep this from 
happening and
I can't think of one reason why you would want it to be this way.

Please someone enlighten me.

Thanks,
Steve

-- 

"They that give up essential liberty to obtain temporary safety,
deserve neither liberty nor safety."  (Ben Franklin)

"The course of history shows that as a government grows, liberty
decreases."  (Thomas Jefferson)




^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2011-10-09  1:35 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-10-08  2:08 SNAT before IPSEC - why? Stephen Clark
2011-10-08  8:06 ` Chris Wilson
2011-10-08 21:15   ` Stephen Clark
2011-10-08  9:13 ` Michal Kubecek
2011-10-08  9:26 ` Jan Engelhardt
2011-10-08 21:09   ` Stephen Clark
2011-10-08 22:27     ` Jan Engelhardt
2011-10-09  1:01       ` Stephen Clark
2011-10-09  1:12         ` Stephen Clark
2011-10-09  1:35           ` Jan Engelhardt

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.