ovs-monitor-ipsec: Allow IKE fragmentation
authorJustin Pettit <jpettit@nicira.com>
Wed, 27 Apr 2011 15:46:38 +0000 (08:46 -0700)
committerJustin Pettit <jpettit@nicira.com>
Wed, 27 Apr 2011 15:46:38 +0000 (08:46 -0700)
Some (broken) firewalls do not properly pass UDP fragments, which will
prevent IKE from completing.  This commit enables the racoon option to
allow application-level fragmenting and allow security associations to
be created.

debian/ovs-monitor-ipsec

index febd5691d3ebdb4caed920cd835bc3be25995eed..0a97c88dc5721d9d418ba9cc6989e20c7a047ced 100755 (executable)
@@ -83,6 +83,7 @@ path certificate "%s";
     cert_entry = """remote %s {
         exchange_mode main;
         nat_traversal on;
+        ike_frag on;
         certificate_type x509 "%s" "%s";
         my_identifier asn1dn;
         peers_identifier asn1dn;