Commit 50f2ffad authored by Franco Fichtner's avatar Franco Fichtner

ipsec: filtertunnel kind of helps, but is the wrong approach

parent 99c71c85
...@@ -130,12 +130,10 @@ function activate_sysctls() ...@@ -130,12 +130,10 @@ function activate_sysctls()
global $config; global $config;
$sysctls = array( $sysctls = array(
'net.inet.ipsec.filtertunnel' => '1', 'net.enc.in.ipsec_bpf_mask' => '2', /* after processing */
'net.inet6.ipsec6.filtertunnel' => '1', 'net.enc.in.ipsec_filter_mask' => '2', /* after processing */
'net.enc.in.ipsec_bpf_mask' => '0x0002', 'net.enc.out.ipsec_bpf_mask' => '1', /* before processing */
'net.enc.in.ipsec_filter_mask' => '0x0002', 'net.enc.out.ipsec_filter_mask' => '1', /* before processing */
'net.enc.out.ipsec_bpf_mask' => '0x0001',
'net.enc.out.ipsec_filter_mask' => '0x0001',
); );
if (isset($config['sysctl']['item'])) { if (isset($config['sysctl']['item'])) {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment