Project

General

Profile

Feature #278

Strongswan don't support port ranges in left/rightprotoport

Added by J├╝rgen Meier almost 8 years ago. Updated over 6 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Category:
charon
Target version:
Start date:
11.01.2013
Due date:
Estimated time:
Resolution:
Fixed

Description

A support of port ranges in ipsec.conf parameters left/rightprotoport is very helpful to split udp applications on different SAs if the peer has only one IP Address.

History

#1 Updated by Martin Willi almost 8 years ago

  • Assignee deleted (Andreas Steffen)
  • Target version deleted (5.0.2)

charon can handle port ranges internally for IKEv2. However, the Linux kernel does not (and probably never will) support port ranges. While extending our configuration backend would be trivial, it wouldn't be of any use.

#2 Updated by Martin Willi over 6 years ago

  • Status changed from New to Closed
  • Assignee set to Martin Willi
  • Target version set to 5.2.0
  • Resolution set to Fixed

Starting with 5.1.0, port ranges can be configured for left/rightsubnet selectors, refer to ipsec.conf(5) for details.

However, none of our kernel backends support such ranges. As it is unlikely that such an extension will be accepted by the Linux networking folks, we can't do much about it.

Also available in: Atom PDF