Re: IPSec VPNs: to gif or not to gif

From: Bill Swingle (unfurl_at_dub.net)
Date: 10/26/03

  • Next message: Brett Glass: "Best way to filter "Nachi pings"?"
    Date: 26 Oct 2003 08:52:22 -0800
    Date: Sun, 26 Oct 2003 08:52:22 -0800
    To: "G. Panula" <greg.panula@lexisnexis.com>
    
    
    

    On Thu, Oct 23, 2003 at 06:23:03AM -0500, G. Panula wrote:
    > Current behavior is encrypted packet is handled by ipfw once, then after
    > decryption it is only handled by ipfw(again) if it passes thru an
    > interface didn't arrive on.

    Does this apply to ipfilter as well?

    -Bill

    -- 
    -=| Bill Swingle - <unfurl@(dub.net|freebsd.org)>
    -=| Every message PGP signed
    -=| PGP Fingerprint: C1E3 49D1 EFC9 3EE0 EA6E  6414 5200 1C95 8E09 0223
    -=| "Computers are useless. They can only give you answers" Pablo Picasso 
    
    



  • Next message: Brett Glass: "Best way to filter "Nachi pings"?"

    Relevant Pages

    • Re: IPSec VPNs: to gif or not to gif
      ... >Current behavior is encrypted packet is handled by ipfw once, ... >decryption it is only handled by ipfwif it passes thru an ... >interface didn't arrive on. ...
      (FreeBSD-Security)
    • Re: IPSec VPNs: to gif or not to gif
      ... >> Current behavior is encrypted packet is handled by ipfw once, ... >> decryption it is only handled by ipfwif it passes thru an ... To unsubscribe, ...
      (FreeBSD-Security)