Age | Commit message (Collapse) | Author |
|
Fix the error message for undefined intf name in error message.
Also, add changes to incorporate mark's from range 0-2047.
Print warning if a vti interface is defined but not used. Hopefully
this will help users understand that they have a partial configuration.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
interval
|
|
|
|
|
|
ipsec or rsa-key config tree.
|
|
ran everytime there was a change in pptp or l2tp configs as well.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
of just for GRE
|
|
|
|
|
|
doesn't fail on ==
|
|
specifically for GRE more protocols can be added in the future if required.
|
|
process the rest of the config
|
|
with support.
|
|
that appear. We should die when an error is found and stop processing the file
|
|
|
|
|
|
(cherry picked from commit ef7acbaef8ccd9305644f22ddb6df1ca985fcf4a)
|
|
|
|
|
|
this time).
|
|
* high-level operations should not access CLI implementation details.
|
|
|
|
|
|
* add commment for op-mode commands' dependency on config-mode check
|
|
dynamic peer when using FQDN identifier for remote end
* allow remote peer with dynamic IP to connect using Main Mode/PSK
|
|
|
|
i.e. use vhost:%priv,%no instead of %priv,%no. Previously
used notation was never supposed to work. Corrected notation
is what we use in l2tp/ipsec as well and is also recommended
otherwise.
2. cannot use leftsourceip to add route when right-subnet is not
specific is based on generalized private,public networks
|
|
* remove copy-tos field under 'vpn ipsec'. It's not
supposed to work with NETKEY
|
|
|
|
|