aboutsummaryrefslogtreecommitdiffstats
path: root/src/charon/config/peer_cfg.h
Commit message (Collapse)AuthorAgeFilesLines
* returning reference pointer on get_ref()Martin Willi2008-05-061-7/+3
|
* implemented IKE_SA uniqueness using ipsec.conf uniqueids paramaterMartin Willi2008-04-141-1/+27
| | | | additionally supports a "keep" value to keep the old IKE_SA
* using dpd actions to enforce connection stateMartin Willi2008-04-111-34/+3
| | | | dpd actions a per child-, not peer ike-sa
* implementation of an CFG attribute framework, currently supporting virtual IPsMartin Willi2008-04-091-13/+8
| | | | | | updated ipsec.conf sourceip parameter to support CIDR notatation to serve from a pool %poolname to query a separate (database?) pool
* fixed two other memory leaksTobias Brunner2008-04-031-1/+1
|
* mediation extension adapted to the naming convention of the current version ↵Tobias Brunner2008-03-261-5/+5
| | | | of the draft. note: the external interface (config, autotools) has not yet been changed
* added equals() method to peer_cfg, ike_cfg, proposals, auth_infoMartin Willi2008-03-261-0/+10
| | | | | | allows easier merging of ipsec.conf connections replaced some iterators through enumerators made proposals algorithm_t private using enumerator
* merged the modularization branch (credentials) back to trunkMartin Willi2008-03-131-109/+66
|
* implemented Expanded EAP types to support vendor specific methodsMartin Willi2007-12-131-1/+8
|
* implemented RFC4478 (repeated authentication)Martin Willi2007-11-201-21/+23
| | | | | changed %V printf handler to take a time delta, %#V now takes two arguments
* experimental P2P-NAT-T for IKEv2 merged back from branchTobias Brunner2007-10-031-1/+38
|
* moved force_encap to ike_config, enables responder to enforce udp encapsulationMartin Willi2007-10-011-10/+1
| | | | fixed bugs in force_encap code
* implemented IKEv2 force_encap connection parameterMartin Willi2007-10-011-3/+12
| | | | | enforces UDP encapsulation by faking NAT detection payloads to hurdle restrictive firewalls
* peer_cfg now knows about group membershipsAndreas Steffen2007-09-131-5/+16
|
* added mobike=yes|no connection optionMartin Willi2007-08-291-1/+10
| | | | | | | yes: include mobike support notifies as initiator no: only enable mobike as responder when initiator supports it default: yes
* support for virtual IP definition on client side:Martin Willi2007-05-221-14/+21
| | | | | | | if leftsourceip is defined, it is requested. server may define rightsourceip=%config to accept any, or it may overwrite it using rightsourceip. if server does not return an IP, client enforces its configured leftsourceip.
* cleaned up apidocMartin Willi2007-04-111-2/+18
| | | | | | added some comments removed configuration.[ch], as it does not make sense like it is
* restructured file layoutMartin Willi2007-04-101-0/+345
new configuration structure: peer_cfg: configuration related to a peer (authenitcation, ...= ike_cfg: config to use for IKE setup (proposals) child_Cfg: config for CHILD_SA (proposals, traffic selectors) a peer_cfg has one ike_cfg and multiple child_cfg's stroke now uses fixed count of threads