netdev
[Top] [All Lists]

Re: [netfilter-core] [NETFILTER] Apply IPsec to ipt_REJECT packets

To: Patrick McHardy <kaber@xxxxxxxxx>
Subject: Re: [netfilter-core] [NETFILTER] Apply IPsec to ipt_REJECT packets
From: Harald Welte <laforge@xxxxxxxxxxxxx>
Date: Wed, 24 Nov 2004 08:29:53 +0100
Cc: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>, netdev@xxxxxxxxxxx, coreteam@xxxxxxxxxxxxx
In-reply-to: <41A3CD45.4080802@xxxxxxxxx>
References: <20041123084225.GA3514@xxxxxxxxxxxxxxxxxxx> <41A37EC0.8010901@xxxxxxxxx> <20041123211630.GA9805@xxxxxxxxxxxxxxxxxxx> <41A3AF41.4010700@xxxxxxxxx> <20041123221900.GA10099@xxxxxxxxxxxxxxxxxxx> <41A3CD45.4080802@xxxxxxxxx>
Sender: netdev-bounce@xxxxxxxxxxx
User-agent: Mutt/1.5.6+20040907i
On Wed, Nov 24, 2004 at 12:52:37AM +0100, Patrick McHardy wrote:

> I would prefer something like this (based on your patch, untested). 
> Currently
> ICMP packets are handled different than TCP packets, saddr is set to 0 for
> them if it is non-local, so they can't be source-routed properly. This patch
> also uses route_reverse for ICMP packets, properly sets fl->proto for output
> routed packets and adds a call to xfrm_lookup for input routed packets.

Just a quick side note: Once we've found a final solution, please don't
forget to merge the changes to ip6t_REJECT in patch-o-matic.

> Regards
> Patrick
-- 
- Harald Welte <laforge@xxxxxxxxxxxxx>             http://www.netfilter.org/
============================================================================
  "Fragmentation is like classful addressing -- an interesting early
   architectural error that shows how much experimentation was going
   on while IP was being designed."                    -- Paul Vixie

Attachment: signature.asc
Description: Digital signature

<Prev in Thread] Current Thread [Next in Thread>