[strongSwan-dev] install policy to kernel using netlink_xfrm

유현 finalyu at gmail.com
Mon Sep 17 03:53:32 CEST 2012


Hi, *

I have one question about installing policy to kernel.

strongSwan sets policies for three directions(XFRM_POLICY_IN,
XFRM_POLICY_OUT, XFRM_POLICY_FWD) in tunnel mode.

I think only XFRM_POLICY_OUT is checked to encrypt packet.. right?

Why install XFRM_POLICY_IN and XFRM_POLICY_FWD ?

Thank you,
Hyun
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/dev/attachments/20120917/0f667b0b/attachment.html>


More information about the Dev mailing list