summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorChris Buechler <cmb@pfsense.org>2015-03-03 00:16:33 -0600
committerChris Buechler <cmb@pfsense.org>2015-03-03 00:18:50 -0600
commit911cc213abd60d2d090778a080ac144e9501716a (patch)
treeedd1615a5e2369d3a9fd8bc7a9c671c3444a4948 /etc
parentc8703520b5c4b39c7363a67267ae94dae1660e48 (diff)
downloadpfsense-911cc213abd60d2d090778a080ac144e9501716a.zip
pfsense-911cc213abd60d2d090778a080ac144e9501716a.tar.gz
Remove "Prefer old SA" option, and ignore it in all existing configurations. Breaks things in many cases with strongSwan. For the very rare circumstances where this is actually desirable, it's just a sysctl that can be set in tunables.
Diffstat (limited to 'etc')
-rw-r--r--etc/inc/vpn.inc10
1 files changed, 0 insertions, 10 deletions
diff --git a/etc/inc/vpn.inc b/etc/inc/vpn.inc
index d4a0e55..eb5eaf2 100644
--- a/etc/inc/vpn.inc
+++ b/etc/inc/vpn.inc
@@ -105,8 +105,6 @@ function vpn_ipsec_configure($restart = false)
unlink_if_exists("{$g['vardb_path']}/ipsecpinghosts");
touch("{$g['vardb_path']}/ipsecpinghosts");
- vpn_ipsec_configure_preferoldsa();
-
$syscfg = $config['system'];
$ipseccfg = $config['ipsec'];
if (!isset($ipseccfg['enable'])) {
@@ -1769,12 +1767,4 @@ EOD;
return 0;
}
-function vpn_ipsec_configure_preferoldsa() {
- global $config;
- if(isset($config['ipsec']['preferoldsa']))
- set_single_sysctl("net.key.preferred_oldsa", "-30");
- else
- set_single_sysctl("net.key.preferred_oldsa", "0");
-}
-
?>
OpenPOWER on IntegriCloud