Subject: Re: IPv4 fast routing versus IPSEC
To: der Mouse <mouse@Rodents.Montreal.QC.CA>
From: None <itojun@iijlab.net>
List: tech-net
Date: 02/25/2003 10:03:03
>>>| date: 1999/10/26 09:53:17; author: itojun; state: Exp; lines: +6 -1
>>>| disable ipflow (IPv4 fast fowarding) when IPsec is configured into the kernel.
>>> Why is this the case?
ipsec policy engine is some sort of packet filter. it is not friendly
with ipflow. for instance, if some traffic hits ipflow cache, it won't
be encrypted.
itojun