Re: [PROBLEM] IPSec: IPComp CPI size

From: David S. Miller (davem@redhat.com)
Date: Thu Aug 14 2003 - 21:57:34 EST


On Fri, 15 Aug 2003 12:51:16 +1000 (EST)
James Morris <jmorris@xxxxxxxxxxxxxxxx> wrote:

> IKE needs to specify the range of the SPI. Both pfkey and the
> native xfrm interfaces support this.

Yes, but in the kernel we need to restrict whatever range
we get so that it'll work for IPCOMP SPIs.

I remember that the KAME kernel bits did this for the app,
and thus we probably need to as well.
-
To unsubscribe from this list: send the line "unsubscribe linux-net" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html