Implemented IPsec policies restricted to given network interface

This commit is contained in:
Andreas Steffen
2016-04-09 16:51:02 +02:00
parent 7f57c4f9fb
commit c26e4330e7
8 changed files with 66 additions and 14 deletions
+3
View File
@@ -691,6 +691,9 @@ connections.<conn>.children.<child>.priority = 0
high-priority drop policies. The default of _0_ uses dynamically calculated
priorities based on the size of the traffic selectors.
connections.<conn>.children.<child>.interface =
Optional interface name to restrict IPsec policies.
connections.<conn>.children.<child>.mark_in = 0/0x00000000
Netfilter mark and mask for input traffic.