From owner-freebsd-security@FreeBSD.ORG Fri Oct 24 04:40:15 2003 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 9041716A4B3 for ; Fri, 24 Oct 2003 04:40:15 -0700 (PDT) Received: from highland.isltd.insignia.com (highland.isltd.insignia.com [195.74.141.1]) by mx1.FreeBSD.org (Postfix) with ESMTP id 6A36443FB1 for ; Fri, 24 Oct 2003 04:40:12 -0700 (PDT) (envelope-from subscriber@insignia.com) Received: from dailuaine.isltd.insignia.com (dailuaine.isltd.insignia.com [172.16.64.11])h9OBeBf2076327 for ; Fri, 24 Oct 2003 12:40:11 +0100 (BST) (envelope-from subscriber@insignia.com) Received: from tomatin (tomatin [172.16.64.128])h9OBeBSX086937 for ; Fri, 24 Oct 2003 12:40:11 +0100 (BST) (envelope-from subscriber@insignia.com) From: Jim Hatfield To: freebsd-security@freebsd.org Date: Fri, 24 Oct 2003 12:40:11 +0100 Organization: Insignia Solutions Message-ID: References: <3203DF3DDE57D411AFF4009027B8C3674B4927@exchange-uk.isltd.insignia.com> In-Reply-To: <3203DF3DDE57D411AFF4009027B8C3674B4927@exchange-uk.isltd.insignia.com> X-Mailer: Forte Agent 1.91/32.564 MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: quoted-printable X-Scanned-By: MIMEDefang 2.38 Subject: Re: IPSec VPNs: to gif or not to gif X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 24 Oct 2003 11:40:15 -0000 On Thu, 23 Oct 2003 12:23:03 +0100, in local.freebsd.security you wrote: >The issue was put to bed. >Reference: >http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/netinet/ip_input.c?rev=3D1= .2 >14&content-type=3Dtext/x-cvsweb-markup >http://www.freebsd.org/cgi/cvsweb.cgi/src/sys/netinet/ip_input.c?rev=3D1= .1 >30.2.48&content-type=3Dtext/x-cvsweb-markup >http://docs.freebsd.org/cgi/getmsg.cgi?fetch=3D132950+0+/usr/local/www/d= b/ >text/2001/freebsd-security/20010325.freebsd-security > >Current behavior is encrypted packet is handled by ipfw once, then after > >decryption it is only handled by ipfw(again) if it passes thru an=20 >interface didn't arrive on. Many thanks, that's very helpful. Jim