Re: Question about xfrm by MARK feature

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Gerd v. Egidy
Date: Friday, June 25, 2010 - 12:35 am

Hi Jamal,

thanks for your detailed answer.


yes


I'm using Patricks conntrack zones. And Patrick helped me with a input chain 
in the nat table. The other cases with e.g. a ip clash between local and 
remote net already work.

So only the case with two remotes and same ips is missing.


I planned to avoid looking at the remote gateway ip (to even allow two 
different remote gateways hiding natted behind the same ip) but that would be 
a good fallback solution if my other ideas don't work out.


Didn't know that, very good.

I just contacted the strongswan maintainers about reqids and marks. Let's see 
if this works out...

Kind regards,

Gerd

-- 
Address (better: trap) for people I really don't want to get mail from:
jonas@cactusamerica.com
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Question about xfrm by MARK feature, Gerd v. Egidy, (Wed Jun 23, 9:03 am)
Re: Question about xfrm by MARK feature, Patrick McHardy, (Wed Jun 23, 9:15 am)
Re: Question about xfrm by MARK feature, Gerd v. Egidy, (Wed Jun 23, 3:13 pm)
Re: Question about xfrm by MARK feature, Herbert Xu, (Wed Jun 23, 3:16 pm)
Re: Question about xfrm by MARK feature, jamal, (Thu Jun 24, 5:04 am)
Re: Question about xfrm by MARK feature, Gerd v. Egidy, (Fri Jun 25, 12:35 am)
Re: Question about xfrm by MARK feature, jamal, (Fri Jun 25, 5:43 am)