summaryrefslogtreecommitdiffstatshomepage
path: root/src/compat/compat.h
diff options
context:
space:
mode:
authorJason A. Donenfeld <Jason@zx2c4.com>2017-02-21 19:27:47 +0100
committerJason A. Donenfeld <Jason@zx2c4.com>2017-02-21 20:11:21 +0100
commit1e96d7f29551309f1ab5480e39dcc6124ea89aa0 (patch)
tree81b6febc411c97cb040aea6556a28f9c0be78c6a /src/compat/compat.h
parentextract-keys: respect compat directives (diff)
downloadwireguard-monolithic-historical-1e96d7f29551309f1ab5480e39dcc6124ea89aa0.tar.xz
wireguard-monolithic-historical-1e96d7f29551309f1ab5480e39dcc6124ea89aa0.zip
device: disable ICMP redirects
The xfrm layer does this by checking for secpath, but we don't use secpath, so instead we have to jigger the config value ourselves. This is nearly always desired, since this is often how a wheel-spoke VPN works. There's very little use case for redirects with wireguard. This should be reverted if we ever move the test directly into ip_forward in net/ipv4/ip_forward.c near the call to ip_rt_send_redirect.
Diffstat (limited to 'src/compat/compat.h')
0 files changed, 0 insertions, 0 deletions