ipsec auto --status: more description for bare shunts

"D. Hugh Redelmeier" <[email protected]> Tue, 25 Mar 2003 22:35:08 -0500 (EST)
Newsgroups gmane.network.freeswan.devel
Message-ID <[email protected]>
-----BEGIN PGP SIGNED MESSAGE-----


The the last section of "ipsec auto --status" output contains a list
of bare shunts.

I've changed Pluto to annotate each bare shunt with why it was
intalled.

If none of that makes sense, here is an explanation of bare shunts.

Pluto installs "bare" shunt eroutes in certain conditions.

An eroute is the mechanism used by KLIPS to select processing for
outbound traffic that has been directed to an ipsecN interface.  An
eroute is a rule that says: for traffic from within this subnet,
directed to this subnet, process it this way.  The processing can be
through a tunnel or through a shunt.

A shunt eroute is one that specifies hold, pass, drop, reject, or trap
processing.

In Pluto, tunnel eroutes are associated with state object -- the state
object is Pluto's representation of the tunnel negotiation.

Some shunt eroutes are associated with connections.  For example, if
the connection (conn) was specified with type=pass or type=drop or
type=reject, then Pluto will install a shunt object associated with
that conn.

If an Opportunistic negotiation fails, no connection instance
describes that pair of endpoints.  A shunt is installed, but it is not
associated with a connection.  This is a bare shunt.

KLIPS installs hold shunts when it traps a packet.  Pluto also keeps
track of these as bare shunts.

Hugh Redelmeier
[email protected]  voice: +1 416 482-8253

-----BEGIN PGP SIGNATURE-----
Version: 2.6.3ia
Charset: noconv

iQCVAwUBPoEf78FAuQPManGZAQGCgAP/aCdUDzm5Lajw9ql2F1WOfCRc4ofoA1OG
FOH6qXHiYNxwbzl6GxPgXBpvCOyzW2FvYqlq8P5CtRz+kfL8H1NsSQIYuMJQlRTq
Z2jZ0Yp37LAapfG4/6EQ7YTTx8GQDFnM3eP3FuWpvC6WINvz5wA4HfSCQToVYG8Y
vPulqTd8G6M=
=26Bk
-----END PGP SIGNATURE-----