]> pilppa.com Git - linux-2.6-omap-h63xx.git/commit
[XFRM]: IPsec tunnel wildcard address support
authorPatrick McHardy <kaber@trash.net>
Fri, 13 Jan 2006 22:34:36 +0000 (14:34 -0800)
committerDavid S. Miller <davem@davemloft.net>
Fri, 13 Jan 2006 22:34:36 +0000 (14:34 -0800)
commitee51b1b6cece4dad408feeb0c3c9adb9cbd9f7d9
treebf7f1c6bb864f287d720b167e565ee3799d957b4
parent7b11f69fb5c475f521db79f5fa22104e15842671
[XFRM]: IPsec tunnel wildcard address support

When the source address of a tunnel is given as 0.0.0.0 do a routing lookup
to get the real source address for the destination and fill that into the
acquire message. This allows to specify policies like this:

spdadd 172.16.128.13/32 172.16.0.0/20 any -P out ipsec
        esp/tunnel/0.0.0.0-x.x.x.x/require;
spdadd 172.16.0.0/20 172.16.128.13/32 any -P in ipsec
        esp/tunnel/x.x.x.x-0.0.0.0/require;

Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/ipv4/xfrm4_state.c
net/ipv6/xfrm6_state.c