Re: IPsec vs ssh

>> To be more precise, I don't want ssh packets to be handled
> Off the top of my head, I'm not sure how you would go about excluding
> a single protocol.

I'm tempted to tell you to stop being dense, but I don't know you well
enough to be sure that's what it is.

I think Darren is probably expecting the exception to apply not
strictly to ssh connections but rather to port-22 connections.  I too
think doing anything of the sort for exactly ssh connections will be
very difficult, but port 22 should be relatively easy and, in most
cases, "port 22" is close enough to "ssh" for practical purposes, even
though neither actually strictly implies the other.

