summaryrefslogtreecommitdiff
path: root/debian/openvswitch-ipsec.dirs
diff options
context:
space:
mode:
authorJustin Pettit <jpettit@nicira.com>2010-09-16 19:19:11 -0700
committerJustin Pettit <jpettit@nicira.com>2010-09-22 22:23:23 -0700
commita3acf0b0c46a28d6c891086e054d81dd915eea2e (patch)
tree51ec6dc886bfcfea97440b6ed6eb03586421dbfa /debian/openvswitch-ipsec.dirs
parentf10a03343b5dd77a41dfefad150b65863af38a00 (diff)
downloadopenvswitch-a3acf0b0c46a28d6c891086e054d81dd915eea2e.tar.gz
debian: Add support for GRE-over-IPsec
The ovs-monitor-ipsec daemon monitors the Interface table for GRE entries. If an entry specifies other-config parameters "ipsec-local-ip" and ("ipsec-psk" or "ipsec-cert"), it will create the appropriate security associations so that all GRE traffic to the remote host will be encrypted. In order for the two GRE tunnels to communicate, both sides need to be configured for IPsec with appropriate authentication. Currently, ovs-monitor-ipsec does not support certificate authentication or ensure that an interface is actually attached to a bridge. Both of these issues will be addressed in a forthcoming patch. NB: While GRE-over-IPsec should work on any system with a relatively recent racoon and setkey, it has only been tested on Debian. As such, only Debian packaging has been provided.
Diffstat (limited to 'debian/openvswitch-ipsec.dirs')
-rw-r--r--debian/openvswitch-ipsec.dirs1
1 files changed, 1 insertions, 0 deletions
diff --git a/debian/openvswitch-ipsec.dirs b/debian/openvswitch-ipsec.dirs
new file mode 100644
index 000000000..02130d0e9
--- /dev/null
+++ b/debian/openvswitch-ipsec.dirs
@@ -0,0 +1 @@
+usr/share/openvswitch/scripts