Re: letting traffic flow through a SG by default

"D. Hugh Redelmeier" <[email protected]> Wed, 12 Mar 2003 21:38:24 -0500 (EST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


| From: D. Hugh Redelmeier <[email protected]>

|     conn packetdefault
| 	    leftsubnet=0.0.0.0/0
| 	    also=private-or-clear

Oops:  I meant:

conn packetdefault
	type=tunnel
    	left=%defaultroute
	# leftid is affected by myid=
	leftsubnet=0.0.0.0/0
	right=%opportunistic
	failureshunt=passthrough
	keyingtries=3
	ikelifetime=1h
	keylife=1h
	rekey=no
	auto=route

This must be a 0.0.0.0/0 -> 0.0.0.0/0 eroute, so this cannot be a
policy group.  Otherwise the characteristics are similar to
private-or-clear.

(Thanks, Claudia for pointing this out.)

Hugh Redelmeier
[email protected]  voice: +1 416 482-8253

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQCVAwUBPm/vI8FAuQPManGZAQEW9gQAldN71rgYfvJ127AnEipFnH4CnWrYOuQa
Yzcxm2uqFXpBvYljQErYCib2nBijMMErByQu7rFgEBi5u/VEJRetYHlhtSfWZF/T
8Z+rl5stFvZx4x0MMCfWN2tJMOWDgNktEvovl7pRVEr6Q3/xpp5sUQmq/XGoZdAi
3Bu7k6q5qzY=
=G3LL
-----END PGP SIGNATURE-----