summaryrefslogtreecommitdiffstats
path: root/src
diff options
context:
space:
mode:
authorLuiz Otavio O Souza <luiz@netgate.com>2015-10-31 10:04:20 -0500
committerLuiz Otavio O Souza <luiz@netgate.com>2015-10-31 10:04:20 -0500
commit5f0b15e5e04a6dfa3cd8a0896eb9608622c2eda8 (patch)
tree7d1e79a6d742d6a199a7d167ff26101ae995b655 /src
parentdd8df8e138c21941faf0254a412ab2481fa1df17 (diff)
downloadpfsense-5f0b15e5e04a6dfa3cd8a0896eb9608622c2eda8.zip
pfsense-5f0b15e5e04a6dfa3cd8a0896eb9608622c2eda8.tar.gz
The net.inet.ip.fastforward sysctl is retired now.
Tryforward instead, is always on and is compatible with IPSEC. TAG: tryforward
Diffstat (limited to 'src')
-rw-r--r--src/etc/inc/globals.inc1
-rw-r--r--src/etc/inc/vpn.inc3
2 files changed, 0 insertions, 4 deletions
diff --git a/src/etc/inc/globals.inc b/src/etc/inc/globals.inc
index 7ed8417..7c77f30 100644
--- a/src/etc/inc/globals.inc
+++ b/src/etc/inc/globals.inc
@@ -133,7 +133,6 @@ $sysctls = array("net.inet.ip.portrange.first" => "1024",
"net.inet.tcp.syncookies" => "1",
"net.inet.tcp.recvspace" => "65228",
"net.inet.tcp.sendspace" => "65228",
- "net.inet.ip.fastforwarding" => "0",
"net.inet.tcp.delayed_ack" => "0",
"net.inet.udp.maxdgram" => "57344",
"net.link.bridge.pfil_onlyip" => "0",
diff --git a/src/etc/inc/vpn.inc b/src/etc/inc/vpn.inc
index 1c22f5f..692f9fe 100644
--- a/src/etc/inc/vpn.inc
+++ b/src/etc/inc/vpn.inc
@@ -207,9 +207,6 @@ function vpn_ipsec_configure($restart = false) {
echo gettext("Configuring IPsec VPN... ");
}
- /* fastforwarding is not compatible with ipsec tunnels */
- set_single_sysctl("net.inet.ip.fastforwarding", "0");
-
/* resolve all local, peer addresses and setup pings */
$ipmap = array();
$rgmap = array();
OpenPOWER on IntegriCloud