| Commit message (Collapse) | Author | Age | Files | Lines |
... | |
| |
| |
| |
| |
| |
| |
| | |
fragments
Other implementations send fragments always in an initial message type
even for transaction or quick mode exchanges.
|
| | |
|
| | |
|
| |
| |
| |
| | |
are received
|
| | |
|
| | |
|
| | |
|
| | |
|
|/ |
|
| |
|
| |
|
|
|
|
|
| |
This alert is raised when the establishment of a child SA fails but the
IKE SA is kept.
|
|
|
|
|
| |
This adds support for early versions of the draft that eventually
resulted in RFC 3947.
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
|
|
| |
required
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
|
|
|
|
| |
According to RFC 2409, section 5.5, if PFS is used all proposals MUST
include the selected DH group, so we remove proposals without the
proposed group and remove other DH groups from the remaining proposals.
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
|
|
|
|
| |
Before this change, modified configs that have been updated with ipsec reload,
could properly be started manually, but the old config would get used if
triggered via trap policies.
|
| |
|
| |
|
| |
|
| |
|
|
|
|
| |
Should not be a problem, but makes static analyzers happy.
|
|
|
|
| |
Fixes #229.
|
|
|
|
| |
Also added an option to enumerate addresses on ignored interfaces.
|
| |
|
| |
|
| |
|
| |
|