summaryrefslogtreecommitdiff
path: root/debian
diff options
context:
space:
mode:
authorJustin Pettit <jpettit@nicira.com>2011-04-27 08:46:38 -0700
committerJustin Pettit <jpettit@nicira.com>2011-04-27 08:46:38 -0700
commit73976ebdb054d1a5a2fedb925304b5e0956c20d1 (patch)
treee7e19dde86930099b274a8d23eb2b0a8148b9223 /debian
parent7adfd7bfd18c84d992fd443499c6df4cabc0749f (diff)
downloadopenvswitch-73976ebdb054d1a5a2fedb925304b5e0956c20d1.tar.gz
ovs-monitor-ipsec: Allow IKE fragmentation
Some (broken) firewalls do not properly pass UDP fragments, which will prevent IKE from completing. This commit enables the racoon option to allow application-level fragmenting and allow security associations to be created.
Diffstat (limited to 'debian')
-rwxr-xr-xdebian/ovs-monitor-ipsec1
1 files changed, 1 insertions, 0 deletions
diff --git a/debian/ovs-monitor-ipsec b/debian/ovs-monitor-ipsec
index febd5691d..0a97c88dc 100755
--- a/debian/ovs-monitor-ipsec
+++ b/debian/ovs-monitor-ipsec
@@ -83,6 +83,7 @@ path certificate "%s";
cert_entry = """remote %s {
exchange_mode main;
nat_traversal on;
+ ike_frag on;
certificate_type x509 "%s" "%s";
my_identifier asn1dn;
peers_identifier asn1dn;