Commit c0cb9dbc authored by Franco Fichtner's avatar Franco Fichtner

system: set filtertunnel for IPsec to fix TCP teardown

parent f20640d0
...@@ -130,10 +130,12 @@ function activate_sysctls() ...@@ -130,10 +130,12 @@ function activate_sysctls()
global $config; global $config;
$sysctls = array( $sysctls = array(
"net.enc.in.ipsec_bpf_mask" => "0x0002", 'net.inet.ipsec.filtertunnel' => '1',
"net.enc.in.ipsec_filter_mask" => "0x0002", 'net.inet6.ipsec6.filtertunnel' => '1',
"net.enc.out.ipsec_bpf_mask" => "0x0001", 'net.enc.in.ipsec_bpf_mask' => '0x0002',
"net.enc.out.ipsec_filter_mask" => "0x0001" 'net.enc.in.ipsec_filter_mask' => '0x0002',
'net.enc.out.ipsec_bpf_mask' => '0x0001',
'net.enc.out.ipsec_filter_mask' => '0x0001',
); );
if (isset($config['sysctl']['item'])) { if (isset($config['sysctl']['item'])) {
......
Markdown is supported
0% or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment