Commit 50f2ffad authored by Franco Fichtner's avatar Franco Fichtner

ipsec: filtertunnel kind of helps, but is the wrong approach

parent 99c71c85
......@@ -130,12 +130,10 @@ function activate_sysctls()
global $config;
$sysctls = array(
'net.inet.ipsec.filtertunnel' => '1',
'net.inet6.ipsec6.filtertunnel' => '1',
'net.enc.in.ipsec_bpf_mask' => '0x0002',
'net.enc.in.ipsec_filter_mask' => '0x0002',
'net.enc.out.ipsec_bpf_mask' => '0x0001',
'net.enc.out.ipsec_filter_mask' => '0x0001',
'net.enc.in.ipsec_bpf_mask' => '2', /* after processing */
'net.enc.in.ipsec_filter_mask' => '2', /* after processing */
'net.enc.out.ipsec_bpf_mask' => '1', /* before processing */
'net.enc.out.ipsec_filter_mask' => '1', /* before processing */
);
if (isset($config['sysctl']['item'])) {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment