vici: Make IP-TFS mode configurable

This commit is contained in:
Tobias Brunner
2025-05-28 16:37:46 +02:00
parent e175abaf89
commit 1afc76dd56
2 changed files with 4 additions and 2 deletions
+1
View File
@@ -904,6 +904,7 @@ CALLBACK(parse_mode, bool,
{ "tunnel", MODE_TUNNEL },
{ "transport", MODE_TRANSPORT },
{ "transport_proxy", MODE_TRANSPORT },
{ "iptfs", MODE_IPTFS },
{ "beet", MODE_BEET },
{ "drop", MODE_DROP },
{ "pass", MODE_PASS },
+3 -2
View File
@@ -920,12 +920,13 @@ connections.<conn>.children.<child>.hostaccess = no
Hostaccess variable to pass to **updown** script.
connections.<conn>.children.<child>.mode = tunnel
IPsec Mode to establish (_tunnel_, _transport_, _transport_proxy_, _beet_,
_pass_ or _drop_).
IPsec Mode to establish (_tunnel_, _transport_, _transport_proxy_, _iptfs_,
_beet_, _pass_ or _drop_).
IPsec Mode to establish CHILD_SA with. _tunnel_ negotiates the CHILD_SA
in IPsec Tunnel Mode, whereas _transport_ uses IPsec Transport Mode.
_transport_proxy_ signifying the special Mobile IPv6 Transport Proxy Mode.
_iptfs_ is IP-TFS tunnel mode with aggregation and fragmentation,
_beet_ is the Bound End to End Tunnel mixture mode, working with fixed inner
addresses without the need to include them in each packet.