> From the strongswan view, how to treat this PFP feature? Is there any
> plan to implement this PFP feature for strongswan?

We currently have no plans to implement such a functionality.

> Does also Linux Kernel need to be updated to support PFP
> feature?

Probably not. XFRM sends the details of the packet triggering the SA to
the keying daemon. Based on that, charon could negotiate SAs specific to
this traffic selector.

Regards
Martin


_______________________________________________
Dev mailing list
[email protected]
https://lists.strongswan.org/mailman/listinfo/dev

Reply via email to