From: "Michal Růžička" <michal.ruzicka@comstar.cz>
To: <hadi@cyberus.ca>
Cc: <davem@davemloft.net>, <kuznet@ms2.inr.ac.ru>, <netdev@vger.kernel.org>
Subject: Re: AF_KEY extended xfrm_state selector handling
Date: Fri, 20 Oct 2006 10:56:13 +0200 [thread overview]
Message-ID: <00b501c6f425$a0325be0$2303a8c0@mruzicka> (raw)
In-Reply-To: 1161305972.5034.58.camel@jzny2
>
> BTW, why not use xfrm instead? Then you dont have to worry about racoon.
What do you mean by this?
- Do you suggest that there is another IKE implemetation for Linux 2.6 IPSec
stack which uses netlink socket (XFRM) for kernel communication? If so,
would you please point me to it?
Or
- Do you mean to make racoon use the netlink socket (XFRM) instead of PF_KEY
for the kernel communication? (Well I'm not brave enough to tackle that.)
Or
- Do you mean something completely else?
> Unless you care about running this in some other OS (I suspect these
> OSes probably have made use of SADB_EXT_ADDRESS_PROXY so that may be a
> futile effort in any case).
I can see this might be problem, but a conditional compilation of the
relevant bits of racoon should be enough to cope with that.
>
>
> cheers,
> jamal
>
> PS:- Nothing stands out for me in your patch, so i have no comment; i
OK, could you please apply it then?
> wasnt sure if the concept of tcp/udp port meant much to the concept of a
> security association
It is crucial for the multiple clients behind the same NAT scenario.
>
>
Regards Michal
next prev parent reply other threads:[~2006-10-20 8:58 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2006-10-19 17:26 AF_KEY extended xfrm_state selector handling Michal Ruzicka
2006-10-20 0:59 ` jamal
2006-10-20 8:56 ` Michal Růžička [this message]
2006-10-20 9:52 ` David Miller
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='00b501c6f425$a0325be0$2303a8c0@mruzicka' \
--to=michal.ruzicka@comstar.cz \
--cc=davem@davemloft.net \
--cc=hadi@cyberus.ca \
--cc=kuznet@ms2.inr.ac.ru \
--cc=netdev@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox