> On Oct 30, 2017, at 12:27 PM, Paul Wouters <paul at nohats.ca> wrote: > > It's not supported by our code. I'm not sure if XFRM has a way of > communicating this IPsec SA property to the kernel. If it does, > then we can surely add support for it. What about the decap-dscp ip xfrm flag? -- cm