summaryrefslogtreecommitdiff
path: root/conf/plugins/kernel-libipsec.opt
diff options
context:
space:
mode:
Diffstat (limited to 'conf/plugins/kernel-libipsec.opt')
-rw-r--r--conf/plugins/kernel-libipsec.opt7
1 files changed, 7 insertions, 0 deletions
diff --git a/conf/plugins/kernel-libipsec.opt b/conf/plugins/kernel-libipsec.opt
new file mode 100644
index 000000000..e76db63d9
--- /dev/null
+++ b/conf/plugins/kernel-libipsec.opt
@@ -0,0 +1,7 @@
+charon.plugins.kernel-libipsec.allow_peer_ts = no
+ Allow that the remote traffic selector equals the IKE peer.
+
+ Allow that the remote traffic selector equals the IKE peer. The route
+ installed for such traffic (via TUN device) usually prevents further IKE
+ traffic. The fwmark options for the _kernel-netlink_ and _socket-default_
+ plugins can be used to circumvent that problem.