diff options
author | Reyk Floeter <reyk@cvs.openbsd.org> | 2012-11-29 15:08:09 +0000 |
---|---|---|
committer | Reyk Floeter <reyk@cvs.openbsd.org> | 2012-11-29 15:08:09 +0000 |
commit | 1bdab4f147158a9e9d8e8b796a7ae3a8fb71e70c (patch) | |
tree | 134877b7f8dac0c65cd29457fae5377a0d669582 /regress | |
parent | 61a5037d0d5b16a1ed89511e0ee1752c432523e4 (diff) |
Prevent VPN traffic leakages in dual-stack hosts/networks.
See http://tools.ietf.org/html/draft-gont-opsec-vpn-leakages.
We forcibly block IPv6 traffic by loading a "flow esp out from ::/0 to
::/0 type deny" unless the protocol is used in any of the flows. Note
that this will block any IPv6 traffic, superseding routes and pf, on
the host by default when iked is running with IPv4 flows only. This
auto-blocking feature can be disabled by specifying the "-6" command
line flag to iked.
Thanks to Fernando Gont.
ok mikeb@
Diffstat (limited to 'regress')
0 files changed, 0 insertions, 0 deletions