ipsec auto --status: more description for bare shunts
"D. Hugh Redelmeier" <[email protected]> Tue, 25 Mar 2003 22:35:08 -0500 (EST)
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- The the last section of "ipsec auto --status" output contains a list of bare shunts. I've changed Pluto to annotate each bare shunt with why it was intalled. If none of that makes sense, here is an explanation of bare shunts. Pluto installs "bare" shunt eroutes in certain conditions. An eroute is the mechanism used by KLIPS to select processing for outbound traffic that has been directed to an ipsecN interface. An eroute is a rule that says: for traffic from within this subnet, directed to this subnet, process it this way. The processing can be through a tunnel or through a shunt. A shunt eroute is one that specifies hold, pass, drop, reject, or trap processing. In Pluto, tunnel eroutes are associated with state object -- the state object is Pluto's representation of the tunnel negotiation. Some shunt eroutes are associated with connections. For example, if the connection (conn) was specified with type=pass or type=drop or type=reject, then Pluto will install a shunt object associated with that conn. If an Opportunistic negotiation fails, no connection instance describes that pair of endpoints. A shunt is installed, but it is not associated with a connection. This is a bare shunt. KLIPS installs hold shunts when it traps a packet. Pluto also keeps track of these as bare shunts. Hugh Redelmeier [email protected] voice: +1 416 482-8253 -----BEGIN PGP SIGNATURE----- Version: 2.6.3ia Charset: noconv iQCVAwUBPoEf78FAuQPManGZAQGCgAP/aCdUDzm5Lajw9ql2F1WOfCRc4ofoA1OG FOH6qXHiYNxwbzl6GxPgXBpvCOyzW2FvYqlq8P5CtRz+kfL8H1NsSQIYuMJQlRTq Z2jZ0Yp37LAapfG4/6EQ7YTTx8GQDFnM3eP3FuWpvC6WINvz5wA4HfSCQToVYG8Y vPulqTd8G6M= =26Bk -----END PGP SIGNATURE-----