On Sun, 1 Jun 2003, Mitsuru KANDA / [ISO-2022-JP] $B?@ED(B $B=<(B wrote:
> Anyway, I have one discussion point.
> When we use 'setkey -D', xfrm ipip tunnels are displayed as unspec SAs.
> Do we need to filter out these xfrm_states other than AH/ESP/IPcomp
> in case of PF_KEY based queries?
Good question. We need to either filter them out or make sure they are
displayed as ipip.
Part of the answer will depend on whether we want to expose xfrm-based
ipip tunnels for general use, or only use them internally for ipcomp.
- James
--
James Morris
<jmorris@xxxxxxxxxxxxxxxx>
|