Hi Darren,
Am 30.01.2012 um 18:16 schrieb Darren Reed:
packets that match an entry in the state table. Additionally, there
is a new rule - "decapsulate". This has been designed to allow
filtering on "inner headers" of packets that have been encapsulated
in clear text. It will, for example, allow filtering on IPv4 headers
inside of IPv6 packets (or vice versa.)
Is there a chance this can be made into getting NAT working with IPsec,
i.e. when sending, applying NAT on the inside packet before it goes into IPsec processing
(and vice versa)?