Date: Mon, 13 Dec 2004 12:29:07 +0200 From: "Ari Suutari" <ari@suutari.iki.fi> To: "Andre Oppermann" <andre@freebsd.org> Cc: freebsd-net@freebsd.org Subject: Re: (review request) ipfw and ipsec processing order foroutgoingpackets Message-ID: <017001c4e0fe$99ce36c0$2508473e@sad.syncrontech.com> References: <20041129100949.GA19560@bps.jodocus.org><41AAF696.6ED81FBF@freebsd.org><41AB3A74.8C05601D@freebsd.org><41AB65B2.A18534BF@freebsd.org><41B85729.40F00890@freebsd.org> <Pine.BSF.4.53.0412091605130.95268@e0-0.zab2.int.zabbadoz.net> <08f001c4de83$dfbb1b80$2508473e@sad.syncrontech.com> <41B98307.50D01EDB@freebsd.org>
next in thread | previous in thread | raw e-mail | index | archive | help
Hi, > > All I intend to provide is a way to specify whether you want IPSEC before > or after pfil_hooks. By default it will be as it is today and work > exactly > the same. OK, this sounds like a good step. Maybe the next step could be third choice like 'both before and after' for us who are perhaps over-concerned about security ? Ari S.
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?017001c4e0fe$99ce36c0$2508473e>