diff options
author | Alexander Bluhm <bluhm@cvs.openbsd.org> | 2017-05-11 12:14:44 +0000 |
---|---|---|
committer | Alexander Bluhm <bluhm@cvs.openbsd.org> | 2017-05-11 12:14:44 +0000 |
commit | 44ca2bc5aee9c7efbfa5299e94142e205b893f44 (patch) | |
tree | 112b75f6d0c709d3797ae94f35230eb5f7bebe29 /sys/netinet/tcpip.h | |
parent | ad2227ce541f4680147d70e42e7d4191100ecad4 (diff) |
IPv6 IPsec transport mode did not work if pf is enabled. The
decrypted packets in the input path were not checked with pf. So
with stateful filtering on enc0, direction aware protocols like
ping or TCP did not pass. Add an explicit pf_test() in
ipsec_common_input_cb() for IPv6 transport mode to fix this.
OK mikeb@
Diffstat (limited to 'sys/netinet/tcpip.h')
0 files changed, 0 insertions, 0 deletions