Linux Netfilter discussions
 help / color / mirror / Atom feed
* Argh!  I'm kicking myself
@ 2003-12-19 20:42 Ian Hunter
  2003-12-19 20:59 ` Aldo S. Lagana
                   ` (3 more replies)
  0 siblings, 4 replies; 5+ messages in thread
From: Ian Hunter @ 2003-12-19 20:42 UTC (permalink / raw)
  To: netfilter

For days now I've been trying to figure out how to recompile my Redhat
2.4.20-24.9 kernel to allow masquerading IPSec ESP traffic.  I ran the
much-vaunted "grep -i masq /proc/ksyms" and to my chagrin got nothing back,
but on a lark decided I'd try "iptables -A FORWARD -t nat -i ppp0 -p esp -j
ACCEPT" just to see if it would fly and it did.  Of course.  And now you're
all laughing at me.

Where is this documented, that gre, esp, ah, and the like are acceptable
protocols?  The docs mention icmp, tcp, and udp only.

Is there such a document, or have I discovered a particular cover of the
netfilter doc-hole?

Ian



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2003-12-19 22:06 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-12-19 20:42 Argh! I'm kicking myself Ian Hunter
2003-12-19 20:59 ` Aldo S. Lagana
2003-12-19 21:33 ` pheusion
2003-12-19 21:39 ` pheusion
2003-12-19 22:06 ` Ramin Dousti

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox