Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

linux-ipsec: Re: IPSec: Fragmentation in Linux 2.0.xx IP stack

From: Alan Cox <alan(at)lxorguk.ukuu.org.uk>
Date: Tue Apr 28 1998 - 07:31:24 EDT


> The version I am puting together is based on some old code (Enskip,
> linux-ipsec by JI) and parts of the IPSec found in OpenBSD.

Anything from OpenBSD whose license contains the advertising clause version of the BSD license cannot be mixed with GPL code. Thats why JI's code got chucked in the cosmic trashcan.

> I was wondering if you would have any idea where to put a hook to process
> a complete IP datagram before fragmentation, without causing too much
> overhead in general IP packet processing.

Personal opinion - hook at the device layer. The other approach would be to use 2.1.x and change the destination cache output function to be your processor. Even then the ip_build_xmit case remains. Right now ip_build_xmit is such a huge win its important to keep it.

Maybe change ip based sockets to call

        sk->ip_build_xmit()

and switch on a per socket basis ?

Alan Received on Tue Apr 28 08:22:24 1998

Do you need help?X

This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:10 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library