On Sat, 29 Jul 2006, Masahide NAKAMURA wrote: > Sub policy is introduced. Main and sub policy are applied the same flow. > (Policy that current kernel uses is named as main.) > It is required another transformation policy management to keep IPsec > and Mobile IPv6 lives separate. > Policy which lives shorter time in kernel should be a sub i.e. normally > main is for IPsec and sub is for Mobile IPv6. > (Such usage as two IPsec policies on different database can be used, too.)
Why can't IPSec & MIP transforms be bundled on the same policy? Or, perhaps a different approach is needed, where the disposition of a policy can be to re-submit a packet for another policy match after the current bundle has been traversed (something like NF_REPEAT). - James -- James Morris <[EMAIL PROTECTED]> - To unsubscribe from this list: send the line "unsubscribe netdev" in the body of a message to [EMAIL PROTECTED] More majordomo info at http://vger.kernel.org/majordomo-info.html