Project

General

Profile

Actions

Feature #8544

closed

Routed IPsec using FreeBSD if_ipsec(4) VTI

Added by Jim Pingle almost 6 years ago. Updated over 5 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
IPsec
Target version:
Start date:
05/30/2018
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:

Description

Add routed IPsec using if_ipsec(4) VTI (Virtual Tunnel Interfaces) from FreeBSD 11.1 and later with strongSwan.

  • Add code to create and manage the interfaces like other interfaces (can assign, setup static routes, specific rules, packet capture, NAT, etc)
  • Add a new Phase2 mode for VTI which defines the local and remote ipsec interface endpoints (like gif or tun)
  • Add input validation to restrict usage of VTI to supported cases

To me, I have a patch to commit.

Actions

Also available in: Atom PDF