netdev
[Top] [All Lists]

Re: [PATCH][IPSEC] IPsec policy can be matched by ICMP type and code

To: Masahide Nakamura <nakam@xxxxxxxxxxxxxx>
Subject: Re: [PATCH][IPSEC] IPsec policy can be matched by ICMP type and code
From: "David S. Miller" <davem@xxxxxxxxxx>
Date: Mon, 9 Aug 2004 17:07:05 -0700
Cc: netdev@xxxxxxxxxxx, usagi-core@xxxxxxxxxxxxxx
In-reply-to: <20040809175404.301bd60a@localhost>
References: <20040809175404.301bd60a@localhost>
Sender: netdev-bounce@xxxxxxxxxxx
On Mon, 9 Aug 2004 17:54:04 +0900
Masahide Nakamura <nakam@xxxxxxxxxxxxxx> wrote:

> Thinking of raw socket (in outbound case), the patch supports only
> ICMP; it is out of scope such packet as user-land builds non-ICMP data
> (e.g. TCP/UDP) and sends through raw socket. IMO this behavior is
> enough, however does anybody have comments?

Truly %100 RAW sockets should have their packets untouched by
the kernel.  User wants exactly that packet to be sent onto
the wire.

<Prev in Thread] Current Thread [Next in Thread>