summaryrefslogtreecommitdiff
path: root/sys/netinet/tcpip.h
diff options
context:
space:
mode:
authorAlexander Bluhm <bluhm@cvs.openbsd.org>2017-05-11 12:14:44 +0000
committerAlexander Bluhm <bluhm@cvs.openbsd.org>2017-05-11 12:14:44 +0000
commit44ca2bc5aee9c7efbfa5299e94142e205b893f44 (patch)
tree112b75f6d0c709d3797ae94f35230eb5f7bebe29 /sys/netinet/tcpip.h
parentad2227ce541f4680147d70e42e7d4191100ecad4 (diff)
IPv6 IPsec transport mode did not work if pf is enabled. The
decrypted packets in the input path were not checked with pf. So with stateful filtering on enc0, direction aware protocols like ping or TCP did not pass. Add an explicit pf_test() in ipsec_common_input_cb() for IPv6 transport mode to fix this. OK mikeb@
Diffstat (limited to 'sys/netinet/tcpip.h')
0 files changed, 0 insertions, 0 deletions