Re: Labeled IPsec with NAT

2007-12-11 Thread sreeniva
Hi Joy, >>I am working on setting up Labeled IPsec along with iptables nat >>rules. Once I insert nat related rules, the ipsec connection breaks >>and the system tries to re-negotiate and creates multiple SAs. I am >>using 2.6.19 kernel (with Venkat's MLSXFRM patches & bugfixes). I >>guess those w

Re: Labeled IPsec with NAT

2007-12-11 Thread Joy Latten
>I am working on setting up Labeled IPsec along with iptables nat >rules. Once I insert nat related rules, the ipsec connection breaks >and the system tries to re-negotiate and creates multiple SAs. I am >using 2.6.19 kernel (with Venkat's MLSXFRM patches & bugfixes). I >guess those were i

Labeled IPsec with NAT

2007-12-11 Thread Yogesh Raju Sreenivasan
() call. It seems like we have to fill in the secpath while creating the skbuff, before calling the xfrm_decode_session, for the output flow. Please do let me know if someone has already looked into this issue and would be helpful if you could guide me with this. If someone has already t