Re: Disabling Policy Groups
Michael Richardson <[email protected]>
| Newsgroups | gmane.network.freeswan.devel |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- >>>>> "Sam" == Sam Sgro <[email protected]> writes: Sam> It appears that to disable Policy Groups on a default install, you Sam> need to re-define 5 connections now, not just one. Is this true? Do Sam> we not want to make it simple for users to turn of OE should they Sam> need to? Actually, that's not entirely true. If you want to consistently change them, you need to deal with five. If you want to turn things off, just rm /etc/ipsec.d/policies/private-or-clear (or zero it, or comment out 0.0.0.0/0) I'd like to have an "OEdefault" conn that doesn't exist, but that I can define such that I can override things. What is a pain is setting up the OEnet stuff. ] ON HUMILITY: to err is human. To moo, bovine. | firewalls [ ] Michael Richardson, Sandelman Software Works, Ottawa, ON |net architect[ ] [email protected] http://www.sandelman.ottawa.on.ca/ |device driver[ ] panic("Just another Debian GNU/Linux using, kernel hacking, security guy"); [ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.7 (GNU/Linux) Comment: Finger me for keys iQCVAwUBPkW34IqHRg3pndX9AQFVOwQA7oS/9opXlKr1IZBGZ6XBBh1x1k3Sz5I+ 5da3J1X7i9AsZJGUM85s3Z3qSvCawxXQbvaqjOH6vj6Ki1TO6tXtMnq/4nTAlOrT 8OhFT+ozLQeMYDQFhiMFSNF3TmEAR1wEiNU8c2pE8Fz4tkby/z2f8r0WtPcGW1md vjRd6RgeNZA= =24fa -----END PGP SIGNATURE-----