Van Jacobson's network channels
Posted Feb 2, 2006 12:29 UTC (Thu) by samj
In reply to: Van Jacobson's network channels
Parent article: Van Jacobson's network channels
If it doesn't cost anything, why not? You'd just plug netfilter in before the app and map packet buffers into its address space first. This can all be done in a separate security context too. Looks to me like it would mean a lot less in the way of protocol specific handling and would allow you to chain such tasks easily (eg netfilter->ipsec or netfilter->reverse proxy->web server etc.).
to post comments)