nixos/strongswan-swanctl: update options for strongswan 6.0.5
This commit is contained in:
@@ -1093,6 +1093,19 @@ in
|
||||
all kernel interfaces.
|
||||
'';
|
||||
|
||||
icmp = mkYesNoParam no ''
|
||||
Whether to forward certain ICMP error messages even if their source IP
|
||||
doesn't match the negotiated IPsec policies.
|
||||
|
||||
ICMP error messages, such as Destination Unreachable, Time Exceeded or
|
||||
Fragmentation Needed, may be generated by a host whose IP address isn't
|
||||
included in the negotiated traffic selectors and therefore doesn't match the
|
||||
IPsec policies. If this option is enabled and the kernel supports it, such
|
||||
packets may still be forwarded. As ICMP errors contain parts of the IP
|
||||
packet that triggered them, the kernel will base its decision on a reverse
|
||||
policy lookup using that IP header.
|
||||
'';
|
||||
|
||||
start_action = mkEnumParam [ "none" "trap" "start" "trap|start" ] "none" ''
|
||||
Action to perform after loading the configuration.
|
||||
|
||||
|
||||
Reference in New Issue
Block a user