diff options
author | David Gwynne <dlg@cvs.openbsd.org> | 2024-11-04 02:44:29 +0000 |
---|---|---|
committer | David Gwynne <dlg@cvs.openbsd.org> | 2024-11-04 02:44:29 +0000 |
commit | ea9b1e853898469f993df7e5f6faba8962320e66 (patch) | |
tree | b1cc04d15fd668bb67eb864d259160ffb83ba266 /usr.bin | |
parent | 8fdb465d47e52d1e39e1870413ae2006fb871c84 (diff) |
add a "natt" option that forces negotiation of nat-t (and udpencap).
this is like the -t command line option on iked itself, but you get
to keep the ike listener on port 500 and you can enable this on
specific policies instead of all of them.
this is useful if you're dealing with an org that can't firewall
ESP traffic well and so you need to force the traffic to be udp
encapsulated even if there's no NAT involved.
ok markus@ tobhe@
Diffstat (limited to 'usr.bin')
0 files changed, 0 insertions, 0 deletions