login
Header Space

 
 

Re: Help! I'm having Linux foisted on me! (PF queuing woes)

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Joshua Smith <juicewvu@...>
Cc: OpenBSD Misc Mailing List <misc@...>
Date: Monday, October 22, 2007 - 2:28 pm

Joshua Smith wrote:
[snip]

One example off the top of my head (and ipsec.conf(5)) is the enc0
interface.  You wouldn't set your state-policy to this, but each
individual rule would use if-bound to prevent traffic from going out
your egress when an IPsec SA is removed/expires before the state is
removed/expires (think isakmpd and the various reasons an SA can disappear).

Of course, if I am wrong and if-bound shouldn't be used in this case,
ipsec.conf(5) should be updated appropriately.

-Brian

[demime 1.01d removed an attachment of type application/pgp-signature which had a name of signature.asc]
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Help! I'm having Linux foisted on me! (PF queuing woes), Richard Wilson, (Fri Oct 19, 10:15 am)
Re: Help! I'm having Linux foisted on me! (PF queuing woes), Douglas A. Tutty, (Fri Oct 19, 2:04 pm)
Re: Help! I'm having Linux foisted on me! (PF queuing woes), Sebastian Benoit, (Fri Oct 19, 12:45 pm)
Re: Help! I'm having Linux foisted on me! (PF queuing woes), Henning Brauer, (Sat Oct 20, 10:16 am)
Re: Help! I'm having Linux foisted on me! (PF queuing woes), Brian, (Mon Oct 22, 2:28 pm)
speck-geostationary