netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH 00/10]: Netfilter IPsec support
@ 2005-11-11  3:18 Patrick McHardy
  2005-11-11  5:17 ` David S. Miller
  2005-11-11 10:13 ` Gerd v. Egidy
  0 siblings, 2 replies; 7+ messages in thread
From: Patrick McHardy @ 2005-11-11  3:18 UTC (permalink / raw)
  To: Kernel Netdev Mailing List, Netfilter Development Mailinglist

This is the latest set patches for netfilter IPsec support.
The use of netif_rx for the innermost SA if it used transport
mode has been replaced by explicit NF_HOOK calls in
xfrm{4,6}_input.c.

[NETFILTER]: Remove okfn usage in ip_vs_core.c
[NETFILTER]: Defer fragmentation in ip_output when connection tracking 
is used
[IPV4]: Replace dst_output by ip_dst_output
[IPV6]: Replace dst_output by ip6_dst_output
[IPV4/6]: Netfilter IPsec output hooks
[IPV4/6]: Make input netfilter IPsec processing symetrical to output
[NETFILTER]: Fix xfrm lookup in ip_route_me_harder
[NETFILTER]: Use conntrack information to determine if packet was NATed
[NETFILTER]: Redo policy lookups after NAT when neccessary
[NETFILTER]: Handle NAT in IPsec policy checks

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2005-11-17  2:35 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-11-11  3:18 [PATCH 00/10]: Netfilter IPsec support Patrick McHardy
2005-11-11  5:17 ` David S. Miller
2005-11-11  5:24   ` Patrick McHardy
2005-11-11 10:13 ` Gerd v. Egidy
2005-11-11 12:09   ` Patrick McHardy
2005-11-15 15:50     ` Marco Berizzi
2005-11-17  2:35       ` Patrick McHardy

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).