public inbox for linux-kernel@vger.kernel.org
 help / color / mirror / Atom feed
* IPSEC and bridged interfaces
@ 2006-10-30 16:29 Joerg Platte
  2006-10-31  8:30 ` Jan Engelhardt
  0 siblings, 1 reply; 3+ messages in thread
From: Joerg Platte @ 2006-10-30 16:29 UTC (permalink / raw)
  To: linux-kernel

Hi,

currently I'm using kernel 2.6.18.1 on one of my computers. The router acts as 
an ipsec endpoint and masquerades all packets received via IPSEC.

Today I replaced the local ethernet interface by a bridged interface by 
combining the ethernet interface with a tap interface. I changed the 
interface names in my iptables-based firewall to match the new bridge 
interface name and did not change anything else.

Unfortunately, the kernel does not encrypt incoming packages any more. tcpdump 
reveals, that all received replies (I tested it with ping) are forwarded 
unencrypted, because they are visible on my firewall instead of being 
encrypted. Is this a known problem? Is bridging and IPSEC (maybe with 
masquerading) currently not supported? Or should I forward this issue to 
another mailing list? 

regards,
Jörg


^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2006-10-31 16:19 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-10-30 16:29 IPSEC and bridged interfaces Joerg Platte
2006-10-31  8:30 ` Jan Engelhardt
2006-10-31 16:19   ` Joerg Platte

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox