Age | Commit message (Collapse) | Author |
|
|
|
|
|
Vti tunnel uses fwmark from the kernel skbuff. This value is now internally
allocated instead of getting it from the configuration.
Also fixed 8286 where configuration was allowing both a tunnel and VTI between
the same vpn src/dst.
|
|
When a connection-type is respond (configured using: set vpn ipsec
site-to-site peer <ip-addr> connection-type [initiate | respond]), the device
should not keep trying to key forever.
|
|
Fix the error message for undefined intf name in error message.
Also, add changes to incorporate mark's from range 0-2047.
Print warning if a vti interface is defined but not used. Hopefully
this will help users understand that they have a partial configuration.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
interval
|
|
|
|
|
|
ipsec or rsa-key config tree.
|
|
ran everytime there was a change in pptp or l2tp configs as well.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
of just for GRE
|
|
|
|
|
|
doesn't fail on ==
|
|
specifically for GRE more protocols can be added in the future if required.
|
|
process the rest of the config
|
|
with support.
|
|
that appear. We should die when an error is found and stop processing the file
|
|
|
|
|
|
(cherry picked from commit ef7acbaef8ccd9305644f22ddb6df1ca985fcf4a)
|
|
|
|
|
|
this time).
|
|
* high-level operations should not access CLI implementation details.
|
|
|
|
|
|
* add commment for op-mode commands' dependency on config-mode check
|
|
dynamic peer when using FQDN identifier for remote end
* allow remote peer with dynamic IP to connect using Main Mode/PSK
|
|
|