From: Herbert Xu <herbert@gondor.apana.org.au>
To: "YOSHIFUJI Hideaki / ?$B5HF#1QL@" <yoshfuji@linux-ipv6.org>
Cc: netdev@vger.kernel.org, netfilter-devel@lists.netfilter.org,
kaber@trash.net
Subject: Re: [NF+IPsec 4/6]: Make IPsec input processing symetrical to output
Date: Thu, 27 Oct 2005 22:15:45 +1000 [thread overview]
Message-ID: <20051027121545.GA5530@gondor.apana.org.au> (raw)
In-Reply-To: <20051017.094919.56989341.yoshfuji@linux-ipv6.org>
On Mon, Oct 17, 2005 at 09:49:19AM +0900, YOSHIFUJI Hideaki / ?$B5HF#1QL@ wrote:
>
> Stack should process the packet just once if it is of transport mode.
> (It is okay to process one twice if it is of tunnel mode.)
Thinking about this again, I'm not sure that I agree.
OK, I don't actually care whether we process it once or twice for
pure transport mode, but I think that it is absolutely essential
that LOCAL_IN/LOCAL_OUT see the decapsulated packet instead of
the encrypted version.
Whether it's IPv4 or IPv6, transport mode shouldn't make you lose the
ability to use netfilter to filter out packets.
Now if we can achieve this by sending the packet through netfilter
only once then I'm all for it.
But if for whatever reason we can't do that, then I'd rather have it
go through twice than not see the decapsulated packet at all which is
the case at the moment.
Cheers,
--
Visit Openswan at http://www.openswan.org/
Email: Herbert Xu ~{PmV>HI~} <herbert@gondor.apana.org.au>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
next prev parent reply other threads:[~2005-10-27 12:15 UTC|newest]
Thread overview: 32+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-10-17 0:22 [NF+IPsec 4/6]: Make IPsec input processing symetrical to output Patrick McHardy
2005-10-17 0:49 ` YOSHIFUJI Hideaki / 吉藤英明
2005-10-17 1:24 ` Patrick McHardy
2005-10-17 1:46 ` Herbert Xu
2005-10-25 23:09 ` Patrick McHardy
2005-10-25 23:10 ` Herbert Xu
2005-10-25 23:14 ` Patrick McHardy
2005-10-26 0:39 ` Herbert Xu
2005-10-27 14:42 ` Patrick McHardy
2005-10-30 23:15 ` Patrick McHardy
2005-10-31 3:19 ` Yasuyuki KOZAKAI
2005-11-01 18:39 ` Stephen Frost
[not found] ` <200510310319.j9V3JHNl019752@toshiba.co.jp>
2005-11-01 18:23 ` Patrick McHardy
2005-10-26 4:39 ` James Morris
2005-10-26 7:37 ` Ingo Oeser
2005-10-26 13:37 ` Stephen Frost
2005-10-27 12:15 ` Herbert Xu [this message]
2005-10-27 14:57 ` YOSHIFUJI Hideaki / 吉藤英明
2005-10-27 16:58 ` Patrick McHardy
2005-11-05 6:30 ` Herbert Xu
2005-11-05 7:55 ` Patrick McHardy
2005-11-05 8:39 ` Herbert Xu
2005-11-05 8:58 ` Patrick McHardy
2005-11-05 9:09 ` Herbert Xu
2005-11-05 9:19 ` Patrick McHardy
2005-11-05 9:38 ` Herbert Xu
2005-11-05 9:55 ` Patrick McHardy
2005-11-05 10:01 ` Herbert Xu
2005-11-05 10:05 ` Patrick McHardy
2005-11-05 10:32 ` Yasuyuki KOZAKAI
[not found] ` <200511051032.jA5AWl2l000619@toshiba.co.jp>
2005-11-08 14:01 ` Patrick McHardy
2005-11-05 8:23 ` YOSHIFUJI Hideaki / 吉藤英明
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20051027121545.GA5530@gondor.apana.org.au \
--to=herbert@gondor.apana.org.au \
--cc=kaber@trash.net \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@lists.netfilter.org \
--cc=yoshfuji@linux-ipv6.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).