diff --git a/nixos/modules/services/networking/strongswan-swanctl/swanctl-params.nix b/nixos/modules/services/networking/strongswan-swanctl/swanctl-params.nix index f17d36341e1d..4ceac71e94d6 100644 --- a/nixos/modules/services/networking/strongswan-swanctl/swanctl-params.nix +++ b/nixos/modules/services/networking/strongswan-swanctl/swanctl-params.nix @@ -1093,6 +1093,19 @@ in all kernel interfaces. ''; + icmp = mkYesNoParam no '' + Whether to forward certain ICMP error messages even if their source IP + doesn't match the negotiated IPsec policies. + + ICMP error messages, such as Destination Unreachable, Time Exceeded or + Fragmentation Needed, may be generated by a host whose IP address isn't + included in the negotiated traffic selectors and therefore doesn't match the + IPsec policies. If this option is enabled and the kernel supports it, such + packets may still be forwarded. As ICMP errors contain parts of the IP + packet that triggered them, the kernel will base its decision on a reverse + policy lookup using that IP header. + ''; + start_action = mkEnumParam [ "none" "trap" "start" "trap|start" ] "none" '' Action to perform after loading the configuration.