summaryrefslogtreecommitdiffstats
path: root/etc
diff options
context:
space:
mode:
authorChris Buechler <cmb@pfsense.org>2015-04-04 19:50:04 -0500
committerChris Buechler <cmb@pfsense.org>2015-04-04 19:52:10 -0500
commitc5292060a497a88bdeb5cb9325fb2a5595bbcea1 (patch)
treecc9b1198d6621339e4250c39cef45d47b26b2391 /etc
parent600b4c3bb8a148032348f7d980ba2cfac683306f (diff)
downloadpfsense-c5292060a497a88bdeb5cb9325fb2a5595bbcea1.zip
pfsense-c5292060a497a88bdeb5cb9325fb2a5595bbcea1.tar.gz
Fix up Ticket #4504 implementation. Match config style with other areas. Use a config setting to disable, rather than enable, this functionality since it's enabled by default so the tag isn't necessary in the default config. Remove now unnecessary config upgrade code.
Diffstat (limited to 'etc')
-rw-r--r--etc/inc/upgrade_config.inc3
-rw-r--r--etc/inc/vpn.inc12
2 files changed, 6 insertions, 9 deletions
diff --git a/etc/inc/upgrade_config.inc b/etc/inc/upgrade_config.inc
index 377e458..96f0325 100644
--- a/etc/inc/upgrade_config.inc
+++ b/etc/inc/upgrade_config.inc
@@ -3555,9 +3555,6 @@ function upgrade_115_to_116() {
function upgrade_116_to_117() {
global $config;
- if (is_array($config['ipsec']))
- $config['ipsec']['shuntlaninterfaces'] = true;
-
if (!isset($config['ipsec']['client']) ||
!isset($config['ipsec']['client']['dns_split']) ||
empty($config['ipsec']['client']['dns_split'])) {
diff --git a/etc/inc/vpn.inc b/etc/inc/vpn.inc
index 30d703a..ccfbd12 100644
--- a/etc/inc/vpn.inc
+++ b/etc/inc/vpn.inc
@@ -590,7 +590,7 @@ EOD;
$ipsecconf .= "config setup\n\tuniqueids = {$uniqueids}\n";
$ipsecconf .= "\tcharondebug=\"" . vpn_ipsec_configure_loglevels(true) . "\"\n";
- if (isset($config['ipsec']['shuntlaninterfaces'])) {
+ if (!isset($config['ipsec']['noshuntlaninterfaces'])) {
if ($config['interfaces']['lan']) {
$lanip = get_interface_ip("lan");
if (!empty($lanip) && is_ipaddrv4($lanip)) {
@@ -599,11 +599,11 @@ EOD;
$ipsecconf .= <<<EOD
conn bypasslan
- leftsubnet={$lanip}/32
- rightsubnet={$lansa}/{$lansn}
- authby=never
- type=passthrough
- auto=route
+ leftsubnet = {$lanip}/32
+ rightsubnet = {$lansa}/{$lansn}
+ authby = never
+ type = passthrough
+ auto = route
EOD;
}
OpenPOWER on IntegriCloud