Merge "Add IPsec bypass policy for ICMP for IPv4"

This commit is contained in:
Zuul
2024-11-13 17:36:24 +00:00
committed by Gerrit Code Review

View File

@@ -300,6 +300,19 @@ class StrongswanPuppet(object):
},
}
swanctl.add_connection('ndp', conn)
# Add bypass connection for ping for IPv4.
else:
conn = {
'children': {
'icmpv4-bypass': {
'mode': 'pass',
'start_action': 'trap',
'local_ts': '\"0.0.0.0/0[icmp]\"',
'remote_ts': '\"0.0.0.0/0[icmp]\"',
},
},
}
swanctl.add_connection('ping', conn)
config = {
'platform::strongswan::params::swanctl':