diff options
author | ume <ume@FreeBSD.org> | 2000-11-09 17:55:17 +0000 |
---|---|---|
committer | ume <ume@FreeBSD.org> | 2000-11-09 17:55:17 +0000 |
commit | 3c271834c9968c8ec40e0ddc708392e69561196e (patch) | |
tree | 811a9dcc397fe6cbe718121d7097022c2b212ccd | |
parent | 5bdaf1e43b8c085c5956bd07c13d5d25e4492d3b (diff) | |
download | FreeBSD-src-3c271834c9968c8ec40e0ddc708392e69561196e.zip FreeBSD-src-3c271834c9968c8ec40e0ddc708392e69561196e.tar.gz |
backout my previous commit (KAME PR 296). foo != TUNNEL will
forbid "ANY" SA from being used for tnunel mode.
Reported by: Chris Cason <casonc@netplex.aussie.org>
-rw-r--r-- | sys/netinet6/ipsec.c | 4 |
1 files changed, 0 insertions, 4 deletions
diff --git a/sys/netinet6/ipsec.c b/sys/netinet6/ipsec.c index 6d8022b..87e771f 100644 --- a/sys/netinet6/ipsec.c +++ b/sys/netinet6/ipsec.c @@ -3148,8 +3148,6 @@ ipsec4_tunnel_validate(ip, nxt0, sav) if (nxt != IPPROTO_IPV4) return 0; - if (sav->sah->saidx.mode != IPSEC_MODE_TUNNEL) - return 0; #ifdef _IP_VHL hlen = _IP_VHL_HL(ip->ip_vhl) << 2; #else @@ -3188,8 +3186,6 @@ ipsec6_tunnel_validate(ip6, nxt0, sav) if (nxt != IPPROTO_IPV6) return 0; - if (sav->sah->saidx.mode != IPSEC_MODE_TUNNEL) - return 0; switch (((struct sockaddr *)&sav->sah->saidx.dst)->sa_family) { case AF_INET6: sin6 = ((struct sockaddr_in6 *)&sav->sah->saidx.dst); |