From 69560611971e547ad8c5f0f1f79715ff07786c18 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Mon, 14 Oct 2013 17:10:16 +0200 Subject: [PATCH] ipsec.conf.5: Note about ICMP[v6] message type/code added --- man/ipsec.conf.5.in | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/man/ipsec.conf.5.in b/man/ipsec.conf.5.in index f83c45116..92be67000 100644 --- a/man/ipsec.conf.5.in +++ b/man/ipsec.conf.5.in @@ -858,6 +858,14 @@ Instead of omitting either value can be used to the same effect, e.g. .BR leftsubnet=fec1::1[udp/%any],10.0.0.0/16[%any/53] . +If the protocol is +.B icmp +or +.B ipv6-icmp +the port is interpreted as ICMP message type if it is less than 256 or as type +and code if it is greater or equal to 256, with the type in the most significant +8 bits and the code in the least significant 8 bits. + The port value can alternatively take the value .B %opaque for RFC 4301 OPAQUE selectors, or a numerical range in the form