Commit c0cb9dbc authored by Franco Fichtner's avatar Franco Fichtner

system: set filtertunnel for IPsec to fix TCP teardown

parent f20640d0
......@@ -130,10 +130,12 @@ function activate_sysctls()
global $config;
$sysctls = array(
"net.enc.in.ipsec_bpf_mask" => "0x0002",
"net.enc.in.ipsec_filter_mask" => "0x0002",
"net.enc.out.ipsec_bpf_mask" => "0x0001",
"net.enc.out.ipsec_filter_mask" => "0x0001"
'net.inet.ipsec.filtertunnel' => '1',
'net.inet6.ipsec6.filtertunnel' => '1',
'net.enc.in.ipsec_bpf_mask' => '0x0002',
'net.enc.in.ipsec_filter_mask' => '0x0002',
'net.enc.out.ipsec_bpf_mask' => '0x0001',
'net.enc.out.ipsec_filter_mask' => '0x0001',
);
if (isset($config['sysctl']['item'])) {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment