.\" $OpenBSD: rt.1,v 1.1 1997/09/05 10:07:25 provos Exp $ .\" Copyright 1997 Niels Provos .\" All rights reserved. .\" .\" Redistribution and use in source and binary forms, with or without .\" modification, are permitted provided that the following conditions .\" are met: .\" 1. Redistributions of source code must retain the above copyright .\" notice, this list of conditions and the following disclaimer. .\" 2. Redistributions in binary form must reproduce the above copyright .\" notice, this list of conditions and the following disclaimer in the .\" documentation and/or other materials provided with the distribution. .\" 3. All advertising materials mentioning features or use of this software .\" must display the following acknowledgement: .\" This product includes software developed by Niels Provos. .\" 4. The name of the author may not be used to endorse or promote products .\" derived from this software without specific prior written permission. .\" .\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR .\" IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES .\" OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED. .\" IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT, .\" INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT .\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, .\" DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY .\" THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. .\" .\" Manual page, using -mandoc macros .\" .Dd September 5, 1997 .Dt RT 1 .Os .Sh NAME .Nm rt .Nd create IPSec routing entries .Sh SYNOPSIS .Nm rt .Ar isrc .Ar isrcmask .Ar idst .Ar idstmask .Ar tproto .Ar sport .Ar dport .Ar raddr .Ar spi .Ar fespah .Sh DESCRIPTION The .Nm rt utility creates a routing entry for IPSec. A Security association must already be established with either .Xr photurisd 1 or .Xr ipsecadm 1 . The arguments are: .Pp .Bl -tag -width idstmask_ .It isrc The initial source address. .It isrcmask The network mask for the initial source address. The source address of outgoing packets has to match the address range specified by .Nm isrc and .Nm isrcmask to be routed through IPSec. .It idst The initial destination address. .It idstmask The network mask for the initial destination address. The destination address of outgoing packets has to match the address range specified by .Nm idst and .Nm idstmask to be routed through IPSec. .It tproto The protocol number packets have to match to be routed. Specify -1 as wildcard. .It sport The source port of a packet if applicable. Specify -1 as wildcard. .It dport The destination port aof a packet if applicable. Specify -1 as wildcard. .It raddr The destination address of the security association. If you dont use tunnel mode that will be the same as .Nm idst . .It spi The Security Parameter Index of the security association. .It fespah Specifies the security protocol of the SA. Use either 0 for AH or 1 for ESP. .El .Sh EXAMPLE Route packets for ESP in transport mode: .Pp rt 0.0.0.0 255.255.255.255 remote 255.255.255.255 -1 -1 -1 remote SPI 1 .Pp rt localip 255.255.255.255 remote 255.255.255.255 -1 -1 -1 remote SPI 1 .Sh SEE ALSO .Xr ipsecadm 1 , .Xr netstat 1 , .Xr photurisd 1 .