Let me propose a patch that enables Ngrep to inspect packages
of protocol type AH and ESP, originating with IPsec. This ability
comes handy for me in porting ipsec-tools to GNU/kFreeBSD.
The patch depends, as given here, on the patch variation I submitted
in the recent report #615138, without which the present changes are
only able to detect IPsec under IPv4, not in IPv6.
The present patch has been tested on payloads
ICMP, UDP, TCP, ESP: IPv4 and ah/tunnel, ah/transport
any: IPv4 and esp/tunnel, esp/transport
ICMPv6, UDP, TCP: IPv6 and ah/transport, ah/tunnel
Best regards,
Mats Erik Andersson, DM