Re: Problem with IPSEC tunnel mode

Date: Fri, 22 Apr 2005 23:53:07 +1000
On Fri, Apr 22, 2005 at 03:48:43PM +0200, Wolfgang Walter wrote:
> So linux implements things like i.e. ipcomp in esp-tunnel in ah-tunnel as 
> bundle instead of feeding it for every transformation into the packet receive 
> code again? I assume that incoming packets which are subject to several 
> ipsec-transformations are exactly seen twice in netfilter PREROUTING: first 
> before decapsulation and then after complete decapsulation?

The packet is fed into each transform as you would expect.  However,
the policy check is done only once at the very end (unless raw sockets
are involved in which case it can occur multiple times).

