[Openswan Users] KLIPS eroute selection question (fwd)
paul at xelerance.com
Thu Mar 8 12:16:12 EST 2007
---------- Forwarded message ----------
Date: Thu, 08 Mar 2007 12:05:05 -0500
From: Michael Richardson <mcr at sandelman.ottawa.on.ca>
To: Paul Wouters <paul at xelerance.com>
Subject: Re: [Openswan Users] KLIPS eroute selection question (fwd)
-----BEGIN PGP SIGNED MESSAGE-----
>>>>> "Paul" == Paul Wouters <paul at xelerance.com> writes:
Paul> Shouldnt it pick on longest prefix? Or does it only pick on
Paul> longest prefix of source?
Most specific source first.
Then, among those (if there is more than one), the longest prefix of
So, you have to add additional policies. %trap-mechanisms that build
an appropriate mesh can help (whether keyed from DNS like OE, or from
LDAP, or whatever)
There is no consistent answer that works.
RFC2401 says that each policy is supposed to have a priority, but that
simply turns a tree into a linear search which doesn't scale.
Any priority system can be implemented via some set of actual
prefixes. Pluto could implement the priorities, but it doesn't.
] Bear: "Me, I'm just the shape of a bear." | firewalls [
] Michael Richardson, Xelerance Corporation, Ottawa, ON |net architect[
] mcr at xelerance.com http://www.sandelman.ottawa.on.ca/mcr/ |device driver[
] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)
Comment: Finger me for keys
-----END PGP SIGNATURE-----
More information about the Users