Suggestion: Crypto-target

"Rene Bartsch" <[email protected]>
Newsgroups gmane.linux.network.bridge.ebtables.devel
Message-ID <[email protected]>
Hi,

I want to do a suggestion for a new ebtables target: crypto

That target shouldn't do anything else than passing the data through the
kernel crypto-api.

It should just have the options "engine", "cipher", "crypting key" and
"decrypting key" (engine for selection of the crypto engine e.g. VIA
Padlock).

This would allow to set up a bridge with e.g. an eth and a gre device
using rules passing all traffic from eth to gre through the crypto-api and
vice versa.

Doing such a solution directly in the kernel level with ebtables would

1.) be network layer3 independent (when e.g. using a gre tunnel)

2.) have much less latency (for real-time applications like VoIP,
A/V-multicasting, ...).

3.) be quite easy to set up as you'd just need to create a few ebtables rules

Comments?

Rene





-------------------------------------------------------
This SF.Net email is sponsored by: YOU BE THE JUDGE. Be one of 170
Project Admins to receive an Apple iPod Mini FREE for your judgement on
who ports your project to Linux PPC the best. Sponsored by IBM.
Deadline: Sept. 24. Go here: http://sf.net/ppc_contest.php
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.