diff options
author | tobhe <tobhe@openbsd.org> | 2020-04-23 20:17:48 +0000 |
---|---|---|
committer | tobhe <tobhe@openbsd.org> | 2020-04-23 20:17:48 +0000 |
commit | 0347364bcafdc08a518dbaa9a2e5afa4f10abdc0 (patch) | |
tree | 4148759110cf24272cc8ac3eebb5a884e992cd97 /usr.sbin/bgpd | |
parent | Support SADB_X_EXT_RDOMAIN extension in pfkey dump (-m). (diff) | |
download | wireguard-openbsd-0347364bcafdc08a518dbaa9a2e5afa4f10abdc0.tar.xz wireguard-openbsd-0347364bcafdc08a518dbaa9a2e5afa4f10abdc0.zip |
Add support for switching rdomain on IPsec encryption/decryption.
It can be configured per policy with the new 'rdomain' option
(see iked.conf(5)).
Only the unencrypted (inner) rdomain has to be configured, the
encrypted rdomain is always the one the responsible iked instance
is running in.
The configured rdomain must exist before iked activates the IPsec SAs,
otherwise pfkey will return an error.
ok markus@, patrick@
Diffstat (limited to 'usr.sbin/bgpd')
0 files changed, 0 insertions, 0 deletions