Hoi Willem,
On Mon, Jan 14, 2019 at 03:03:42PM -0500, Willem de Bruijn wrote:
> On Mon, Jan 14, 2019 at 2:12 PM Martijn van Oosterhout wrote:
> > I see a two ways this could be fixed.
> >
> > Option 1: include FLOW_DISSECTOR_KEY_MPLS in
> > flow_keys_dissector_sym
is actually another problem: MPLS provides no information
about the next header because it assumes the endpoints in the network
recognise the MPLS headers. Which means you'd have to make a guess
about what the next layer should be.
Any ideas? Is this the right approach?
Thanks in advance,
-
different* data. So
just skipping the decrypt won't work, you'll just end up sending
packets which the other end can't read.
If your using the same keys, perhaps the kernal can see that, I don't
know...
Hope this helps,
--
Martijn van Oosterhout http://svana.org/kleptog/
>