diff options
author | Jeff Leung <jleung@v10networks.ca> | 2015-01-31 07:37:43 +0000 |
---|---|---|
committer | Jeff Leung <jleung@v10networks.ca> | 2015-02-05 06:30:59 +0000 |
commit | de318d8d25427a27c80206c16dc36c0021dfca2c (patch) | |
tree | 4e0463412f49777319f448b0a4bb046f30cc49c8 /templates | |
parent | 9d20c1dc27d91e362e79221dd773dd9418d5af99 (diff) | |
download | vyatta-cfg-vpn-de318d8d25427a27c80206c16dc36c0021dfca2c.tar.gz vyatta-cfg-vpn-de318d8d25427a27c80206c16dc36c0021dfca2c.zip |
Allow users to specify aggressive mode for IKEv1 key exchanges
Although strongly not recommended by the developers of strongSwan,
sometimes remote VPN gateways requires this because of interop
reasons or a network admin who doesn't have an idea on why
aggressive mode is bad.
Diffstat (limited to 'templates')
-rw-r--r-- | templates/vpn/ipsec/ike-group/node.tag/mode/node.def | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/templates/vpn/ipsec/ike-group/node.tag/mode/node.def b/templates/vpn/ipsec/ike-group/node.tag/mode/node.def new file mode 100644 index 0000000..f302d3d --- /dev/null +++ b/templates/vpn/ipsec/ike-group/node.tag/mode/node.def @@ -0,0 +1,6 @@ +help: IKEv1 Phase 1 Mode Selection +type: txt +default: "main" +syntax:expression: $VAR(@) in "main", "aggressive"; "must be main or aggressive" +val_help: main; Use Main mode for Key Exchanges in the IKEv1 Protocol (Recommended Default) +val_help: ikev2; Use Aggressive mode for Key Exchanges in the IKEv1 protocol - We do not recommend users to use aggressive mode as it is much more insecure compared to Main mode. |