summaryrefslogtreecommitdiff
path: root/sbin/ipsec/rt/rt.1
blob: 3445dc67625b0b28ad24e630ee593c4b8d7b483d (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
.\" $OpenBSD: rt.1,v 1.2 1998/03/05 09:30:52 provos Exp $
.\" Copyright 1997 Niels Provos <provos@physnet.uni-hamburg.de>
.\" All rights reserved.
.\"
.\" Redistribution and use in source and binary forms, with or without
.\" modification, are permitted provided that the following conditions
.\" are met:
.\" 1. Redistributions of source code must retain the above copyright
.\"    notice, this list of conditions and the following disclaimer.
.\" 2. Redistributions in binary form must reproduce the above copyright
.\"    notice, this list of conditions and the following disclaimer in the
.\"    documentation and/or other materials provided with the distribution.
.\" 3. All advertising materials mentioning features or use of this software
.\"    must display the following acknowledgement:
.\"      This product includes software developed by Niels Provos.
.\" 4. The name of the author may not be used to endorse or promote products
.\"    derived from this software without specific prior written permission.
.\"
.\" THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
.\" IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
.\" OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
.\" IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
.\" INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
.\" NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
.\" DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
.\" THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
.\"
.\" Manual page, using -mandoc macros
.\"
.Dd September 5, 1997
.Dt RT 1
.Os
.Sh NAME
.Nm rt
.Nd create IPSec routing entries
.Sh SYNOPSIS
.Nm rt
.Ar isrc
.Ar isrcmask
.Ar idst
.Ar idstmask
.Ar tproto
.Ar sport
.Ar dport
.Ar raddr
.Ar spi
.Ar fespah
.Sh DESCRIPTION
The
.Nm rt
utility creates a routing entry for IPSec. A Security association
must already be established with either
.Xr photurisd 8
or
.Xr ipsecadm 1 .
The arguments are: 
.Pp
.Bl -tag -width idstmask_
.It isrc
The initial source address.
.It isrcmask
The network mask for the initial source address. The source
address of outgoing packets has to match the address range
specified by 
.Nm isrc 
and 
.Nm isrcmask
to be routed through IPSec.
.It idst
The initial destination address.
.It idstmask
The network mask for the initial destination address. The destination
address of outgoing packets has to match the address range
specified by
.Nm idst 
and 
.Nm idstmask
to be routed through IPSec.
.It tproto
The protocol number packets have to match to be routed.
Specify -1 as wildcard.
.It sport
The source port of a packet if applicable. Specify -1 as wildcard.
.It dport
The destination port aof a packet if applicable. Specify -1 as wildcard.
.It raddr
The destination address of the security association. If you dont
use tunnel mode that will be the same as 
.Nm idst .
.It spi
The Security Parameter Index of the security association.
.It fespah
Specifies the security protocol of the SA. Use either 0 for AH or
1 for ESP.
.El
.Sh EXAMPLE
Route packets for ESP in transport mode:
.Pp
rt 0.0.0.0 255.255.255.255 remote 255.255.255.255 -1 -1 -1 remote SPI 1
.Pp
rt localip 255.255.255.255 remote 255.255.255.255 -1 -1 -1 remote SPI 1
.Sh SEE ALSO
.Xr ipsecadm 1 ,
.Xr netstat 1 , 
.Xr photurisd 8 .