packages/net/strongswan
Paul Fertser a8fa557cd5 strongswan: allow to specify per-connection reqid with UCI
This is useful to assign all traffic to a fw3 zone, e.g.:

/etc/config/ipsec:

config remote 'test'
	list tunnel		'dev'
...

config 'tunnel' 'dev'
	option reqid		'33'
...

/etc/config/firewall:

config zone
	option name		wan
	option extra_src	"-m policy --pol none --dir in"
	option extra_dest	"-m policy --pol none --dir out"
...

config zone
	option name		vpn
	# subnet needed for firewall3 before 22 Nov 2019, 8174814a
	list subnet		'0.0.0.0/0'
	option extra_src	"-m policy --pol ipsec --dir in --reqid 33"
	option extra_dest	"-m policy --pol ipsec --dir out --reqid 33"
...

Signed-off-by: Paul Fertser <fercerpav@gmail.com>
2019-11-26 15:27:54 +03:00
..
files strongswan: allow to specify per-connection reqid with UCI 2019-11-26 15:27:54 +03:00
patches strongswan: bump to 5.8.1 2019-09-16 02:28:20 +03:00
Config.in strongswan: collapse menu items 2019-03-27 18:21:54 +01:00
Makefile treewide: add PKG_CPE_ID for better cvescanner coverage 2019-09-17 12:40:26 +02:00