diff options
author | Martin Willi <martin@revosec.ch> | 2014-11-27 19:19:09 +0100 |
---|---|---|
committer | Martin Willi <martin@revosec.ch> | 2014-12-04 11:10:48 +0100 |
commit | a8142a17cff1a420599b30c13568bda1fa0a6653 (patch) | |
tree | 9b104895b091de6f69b90a6b0bedd58ab9480a4c /src/libcharon/plugins/unity/unity_narrow.c | |
parent | 070461b70d7c192bae01a11bf7ee7763bf30fe0e (diff) | |
download | strongswan-a8142a17cff1a420599b30c13568bda1fa0a6653.tar.bz2 strongswan-a8142a17cff1a420599b30c13568bda1fa0a6653.tar.xz |
kernel-wfp: Install inbound ALE IP-in-IP filters
When processing inbound tunnel mode packets, Windows decrypts packets and
filters them as IP-in-IP packets. We therefore require an ALE filter that
calls the FWPM_CALLOUT_IPSEC_INBOUND_TUNNEL_ALE_ACCEPT callout to allow them
when using a default-drop policy.
Without these rules, any outbound packet created an ALE state that allows
inbound packets as well. Processing inbound packets without any outbound
traffic fails without these rules.
Diffstat (limited to 'src/libcharon/plugins/unity/unity_narrow.c')
0 files changed, 0 insertions, 0 deletions