diff options
| author | Justin Pettit <jpettit@nicira.com> | 2011-04-27 08:46:38 -0700 |
|---|---|---|
| committer | Justin Pettit <jpettit@nicira.com> | 2011-04-27 08:46:38 -0700 |
| commit | 73976ebdb054d1a5a2fedb925304b5e0956c20d1 (patch) | |
| tree | e7e19dde86930099b274a8d23eb2b0a8148b9223 /debian | |
| parent | 7adfd7bfd18c84d992fd443499c6df4cabc0749f (diff) | |
| download | openvswitch-73976ebdb054d1a5a2fedb925304b5e0956c20d1.tar.gz | |
ovs-monitor-ipsec: Allow IKE fragmentation
Some (broken) firewalls do not properly pass UDP fragments, which will
prevent IKE from completing. This commit enables the racoon option to
allow application-level fragmenting and allow security associations to
be created.
Diffstat (limited to 'debian')
| -rwxr-xr-x | debian/ovs-monitor-ipsec | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/debian/ovs-monitor-ipsec b/debian/ovs-monitor-ipsec index febd5691d..0a97c88dc 100755 --- a/debian/ovs-monitor-ipsec +++ b/debian/ovs-monitor-ipsec @@ -83,6 +83,7 @@ path certificate "%s"; cert_entry = """remote %s { exchange_mode main; nat_traversal on; + ike_frag on; certificate_type x509 "%s" "%s"; my_identifier asn1dn; peers_identifier asn1dn; |
