kernel-pfkey: Install routes for shunt policies

This commit is contained in:
Tobias Brunner
2014-06-26 18:12:05 +02:00
parent 945e1df738
commit b451303a6c
@@ -2447,12 +2447,12 @@ static status_t add_policy_internal(private_kernel_pfkey_ipsec_t *this,
free(out); free(out);
/* install a route, if: /* install a route, if:
* - this is a forward policy (to just get one for each child) * - this is an inbound policy (to just get one for each child)
* - we are in tunnel mode * - we are in tunnel mode or install a bypass policy
* - routing is not disabled via strongswan.conf * - routing is not disabled via strongswan.conf
*/ */
if (policy->direction == POLICY_IN && if (policy->direction == POLICY_IN && this->install_routes &&
ipsec->cfg.mode != MODE_TRANSPORT && this->install_routes) (mapping->type != POLICY_IPSEC || ipsec->cfg.mode != MODE_TRANSPORT))
{ {
install_route(this, policy, (policy_sa_in_t*)mapping); install_route(this, policy, (policy_sa_in_t*)mapping);
} }