On Sat, 29 Jul 2006, Masahide NAKAMURA wrote:

> Sub policy is introduced. Main and sub policy are applied the same flow.
> (Policy that current kernel uses is named as main.)
> It is required another transformation policy management to keep IPsec
> and Mobile IPv6 lives separate.
> Policy which lives shorter time in kernel should be a sub i.e. normally
> main is for IPsec and sub is for Mobile IPv6.
> (Such usage as two IPsec policies on different database can be used, too.)

Why can't IPSec & MIP transforms be bundled on the same policy?

Or, perhaps a different approach is needed, where the disposition of a 
policy can be to re-submit a packet for another policy match after the 
current bundle has been traversed (something like NF_REPEAT).


- James
-- 
James Morris
<[EMAIL PROTECTED]>
-
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to [EMAIL PROTECTED]
More majordomo info at  http://vger.kernel.org/majordomo-info.html

Reply via email to