diff options
author | Martin Willi <martin@revosec.ch> | 2013-04-20 12:28:05 +0200 |
---|---|---|
committer | Martin Willi <martin@revosec.ch> | 2013-05-06 17:01:13 +0200 |
commit | 580b768d03c10f7ce12ebcb4168e58d752b5e0ab (patch) | |
tree | 34415ebcd4a2772daae881fbf039806da1c2fe1f /src/libhydra/plugins/kernel_pfkey/kernel_pfkey_ipsec.c | |
parent | bd520193a486c6192494f70920702477b843d72e (diff) | |
download | strongswan-580b768d03c10f7ce12ebcb4168e58d752b5e0ab.tar.bz2 strongswan-580b768d03c10f7ce12ebcb4168e58d752b5e0ab.tar.xz |
kernel-pfroute: add a feature flag requesting "exclude" routes
If routes installed along with policies covering the peer address affect local
IKE/ESP packets, they won't get routed correctly. To work around this issue,
the kernel interface can install "exclude" routes for the IKE peer. Not all
networking backends require this workaround, hence we export a flag for it
if it is required.
Diffstat (limited to 'src/libhydra/plugins/kernel_pfkey/kernel_pfkey_ipsec.c')
0 files changed, 0 insertions, 0 deletions