Re: nat,ipsec,pf,routing question

2009-10-30 Thread Stuart Henderson
the lo1 hack is no longer needed here; read OUTGOING NETWORK ADDRESS TRANSLATION in ipsec.conf(5). On 2009-10-29, Christoph Leser le...@sup-logistik.de wrote: I'm sure I have seen the answer to my question here on the list some time ago, but I'm too stupid to find it again: In what order are

nat,ipsec,pf,routing question

2009-10-29 Thread Christoph Leser
I'm sure I have seen the answer to my question here on the list some time ago, but I'm too stupid to find it again: In what order are the following operations performed on an IP packet a. IPSEC ( decides whether a packet matches an IPSEC flow ) b. normal kernel routing c. NAT d. packet filtering