Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 21 Jul 2017 17:09:35 +0700
From:      Eugene Grosbein <eugen@grosbein.net>
To:        Kajetan Staszkiewicz <vegeta@tuxpowered.net>, FreeBSD Net <freebsd-net@freebsd.org>
Subject:   Re: ipsec encryption only via given route
Message-ID:  <5971D2DF.6030904@grosbein.net>
In-Reply-To: <3526072.muFbfPklCK@energia>
References:  <3526072.muFbfPklCK@energia>

next in thread | previous in thread | raw e-mail | index | archive | help
20.07.2017 23:17, Kajetan Staszkiewicz пишет:
> Hey group,

> Can I somehow make IPsec encryption to happen AFTER routing decision and 
> ensure that it happens only when traffic leaves via specified interface?

You may want to upgrade to 11.1-RELEASE and utilize its new if_ipsec(4) feature
targeted for creating route-based VPNs.

https://www.freebsd.org/cgi/man.cgi?query=if_ipsec&apropos=0&sektion=0&manpath=FreeBSD+11.1-RELEASE&arch=default&format=html




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?5971D2DF.6030904>