Netdev List
 help / color / mirror / Atom feed
From: "Michal Růžička" <michal.ruzicka@comstar.cz>
To: <hadi@cyberus.ca>
Cc: <davem@davemloft.net>, <kuznet@ms2.inr.ac.ru>, <netdev@vger.kernel.org>
Subject: Re: AF_KEY extended xfrm_state selector handling
Date: Fri, 20 Oct 2006 10:56:13 +0200	[thread overview]
Message-ID: <00b501c6f425$a0325be0$2303a8c0@mruzicka> (raw)
In-Reply-To: 1161305972.5034.58.camel@jzny2


>
> BTW, why not use xfrm instead? Then you dont have to worry about racoon.

What do you mean by this?
- Do you suggest that there is another IKE implemetation for Linux 2.6 IPSec 
stack which uses netlink socket (XFRM) for kernel communication? If so, 
would you please point me to it?
Or
- Do you mean to make racoon use the netlink socket (XFRM) instead of PF_KEY 
for the kernel communication? (Well I'm not brave enough to tackle that.)
Or
- Do you mean something completely else?

> Unless you care about running this in some other OS (I suspect these
> OSes probably have made use of SADB_EXT_ADDRESS_PROXY so that may be a
> futile effort in any case).

I can see this might be problem, but a conditional compilation of the 
relevant bits of racoon should be enough to cope with that.

>
>
> cheers,
> jamal
>
> PS:- Nothing stands out for me in your patch, so i have no comment; i


OK, could you please apply it then?

> wasnt sure if the concept of tcp/udp port meant much to the concept of a
> security association

It is crucial for the multiple clients behind the same NAT scenario.

>
>

Regards Michal 


  reply	other threads:[~2006-10-20  8:58 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-10-19 17:26 AF_KEY extended xfrm_state selector handling Michal Ruzicka
2006-10-20  0:59 ` jamal
2006-10-20  8:56   ` Michal Růžička [this message]
2006-10-20  9:52     ` David Miller

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='00b501c6f425$a0325be0$2303a8c0@mruzicka' \
    --to=michal.ruzicka@comstar.cz \
    --cc=davem@davemloft.net \
    --cc=hadi@cyberus.ca \
    --cc=kuznet@ms2.inr.ac.ru \
    --cc=netdev@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox