docs:ipsec:policy
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| docs:ipsec:policy [2013/09/27 12:37] – root | docs:ipsec:policy [2013/09/27 12:57] (current) – root | ||
|---|---|---|---|
| Line 2: | Line 2: | ||
| ===== Policy Format ===== | ===== Policy Format ===== | ||
| - | **protocol / mode / src - dst [/level] ** | + | Policy format is **__direction__ |
| + | * '' | ||
| + | * '' | ||
| + | * '' | ||
| + | * '' | ||
| - | **protocol** is either '' | + | ===== Request Format ===== |
| + | Request format for IPSec is **__protocol__ / __mode__ / __src__ - __dst__ [/ __level__]**. | ||
| - | **mode** is either '' | + | * **protocol** is either '' |
| + | * **mode** is either '' | ||
| + | * **src** and **dst** specifies the IPsec endpoint. **src** always means the " | ||
| - | **src** and **dst** specifies the IPsec endpoint. **src** always means the " | + | **level** must be set to one of the following: **default**, |
| - | + | ||
| - | ===== Policy level ===== | + | |
| - | + | ||
| - | The level must be set to one of the following: **default**, | + | |
| * **default** means that the kernel should consult the system default policy defined by sysctl(8), such as net.inet.ipsec.esp_trans_deflev. See ipsec(4) regarding the system default. | * **default** means that the kernel should consult the system default policy defined by sysctl(8), such as net.inet.ipsec.esp_trans_deflev. See ipsec(4) regarding the system default. | ||
docs/ipsec/policy.1380278229.txt.gz · Last modified: 2013/09/27 12:37 by root