|
|||||||||||
|
linux-ipsec: can this work ?!
From: Mark Pilon <mpilon(at)compatible.com>
Date: Mon May 11 1998 - 18:06:19 EDT
Hugh's comments about using freeswan IPSEC and Pluto mirror discussions we're having here with our VPN products -- there are advantages and disadvantages to being either the "tail or the dog" in blazing our own trail or supporting freeswan's IPSEC and Pluto. one complication is that we already _have_ a tunneling router, and so some of our interface is already cast. fortunately not in stone. back to my specific issue, for testing this router I'd like to kick off multiple sessions on a pair of linux workstations, each using different SAs. the problem comes in identifying, down deep in the machine, _which_ SA to apply when it comes time to wrap the packet. current->pid seems to be the pid of the process sending the packets; (sometimes, as w/ FTP I see PIDs of 0 -- the kernel) -- does this seem a workable means to identify who's sending what most of the time? I'm going to play w/ it some more, but I'd appreciate comments from any of you net/kernel experts out there. what network activity happens from within the kernel?
Thanks again,
Mark Pilon
This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 12:59:10 EDT |
||||||||||
|
|||||||||||