Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 13 Dec 2004 12:29:07 +0200
From:      "Ari Suutari" <ari@suutari.iki.fi>
To:        "Andre Oppermann" <andre@freebsd.org>
Cc:        freebsd-net@freebsd.org
Subject:   Re: (review request) ipfw and ipsec processing order foroutgoingpackets
Message-ID:  <017001c4e0fe$99ce36c0$2508473e@sad.syncrontech.com>
References:  <20041129100949.GA19560@bps.jodocus.org><41AAF696.6ED81FBF@freebsd.org><41AB3A74.8C05601D@freebsd.org><41AB65B2.A18534BF@freebsd.org><41B85729.40F00890@freebsd.org> <Pine.BSF.4.53.0412091605130.95268@e0-0.zab2.int.zabbadoz.net> <08f001c4de83$dfbb1b80$2508473e@sad.syncrontech.com> <41B98307.50D01EDB@freebsd.org>

next in thread | previous in thread | raw e-mail | index | archive | help
Hi,
>
> All I intend to provide is a way to specify whether you want IPSEC before
> or after pfil_hooks.  By default it will be as it is today and work 
> exactly
> the same.

    OK, this sounds like a good step. Maybe the next step could be third 
choice
    like 'both before and after' for us who are perhaps over-concerned about 
security ?

        Ari S. 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?017001c4e0fe$99ce36c0$2508473e>