tech-net archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: IPFilter 5.1.1 imported into current



Hi Darren,

Am 30.01.2012 um 18:16 schrieb Darren Reed:
> packets that match an entry in the state table. Additionally, there
> is a new rule - "decapsulate". This has been designed to allow
> filtering on "inner headers" of packets that have been encapsulated
> in clear text. It will, for example, allow filtering on IPv4 headers
> inside of IPv6 packets (or vice versa.)

Is there a chance this can be made into getting NAT working with IPsec,
i.e. when sending, applying NAT on the inside packet before it goes into IPsec 
processing 
(and vice versa)?

In my previous job, we had some hacks for that, and seeing this supported in an 
official way would be nice. 


 - Hubert


Home | Main Index | Thread Index | Old Index