Peter Müller
66c3619872
Early spring clean: Remove trailing whitespaces, and correct licence headers
...
Bumping across one of our scripts with very long trailing whitespaces, I
thought it might be a good idea to clean these up. Doing so, some
missing or inconsistent licence headers were fixed.
There is no need in shipping all these files en bloc, as their
functionality won't change.
Signed-off-by: Peter Müller <peter.mueller@ipfire.org >
2022-02-18 23:54:57 +00:00
Michael Tremer
0de7cc50ac
IPsec: Disable XFRM policy lookup for VTI devices
...
This speeds up throughput slightly
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2021-01-18 13:05:10 +00:00
Michael Tremer
918ee4a4cf
strongswan: Manually install all routes for non-routed VPNs
...
This is a regression from disabling charon.install_routes.
VPNs are routing fine as long as traffic is passing through
the firewall. Traps are not propertly used as long as these
routes are not present and therefore we won't trigger any
tunnels when traffic originates from the firewall.
Fixes : #12045
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-04-08 16:44:57 +01:00
Michael Tremer
3b521c724f
ipsec-interfaces: Apply static routes (again) after creating IPsec interfaces
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-03-18 15:25:48 +00:00
Michael Tremer
f9dd134645
ipsec-interfaces: Resolve any remote hostnames
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
d985ce5ae9
ipsec-interfaces: Move conditional block into the loop
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
517683eeb1
ipsec: Drop VPN_IP setting
...
This is now a per-connection setting
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
6826364580
ipsec-*: Name some more configuration variables
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
1ca2f88a74
ipsec-interfaces: Uses local IP address from connection first, then default
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
c94aa25475
ipsec-interfaces: Fix typo in variable name
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
c821440ced
ipsec: Filter better for GRE/VTI interfaces
...
This tried to delete the GREEN interface before
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
6a45a1f101
ipsec: TTL only applies for GRE interfaces and not VTI
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
54bac01402
ipsec: Find correct RED IP address when using %defaultroute
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
3dc21d43bf
ipsec: Log a message when an interface could not be created
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
1a45f9a70a
ipsec-interfaces: Don't add any interfaces when IPsec is disabled
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
a56357b8be
Revert "ipsec-interfaces: Run when IPsec is disabled"
...
This reverts commit 3c3a1cfdb9b473fae9b792e8c211c9940fafc658.
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
4cf038dcfe
ipsec-interfaces: Run when IPsec is disabled
...
This needs to run even when IPsec is disable to remove
and interfaces
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
05af70c2f3
ipsec-interfaces: Use correct righthost variable
...
Signed-off-by: Michael Tremer <michael.tremer@ipfire.org >
2019-02-04 18:20:36 +00:00
Michael Tremer
b8c153bca5
IPsec: Add (experimental) script that creates GRE/VTI interfaces
...
Signed-off-by: root <root@interim-edge-a.ec2.internal >
2019-02-04 18:20:36 +00:00