[strongSwan-dev] Backward compatibility option for inbound SA/SP marking

Tobias Brunner tobias at strongswan.org
Thu Aug 24 10:43:08 CEST 2017


Hi Christophe,

> I had a look in the mark-inbound-sa branch, I think there are other
> methods where the SA mark must be set: child_sa_t.update,
> child_sa_t.destroy.

You're right, thanks!  (You missed the one in update_usebytes() btw.)

While I appreciate your creating that stroke patch, I probably won't
apply it.  We need to stop adding new features to starter/stroke.  Maybe
that will get people to abandon the legacy interface and switch to
swanctl/vici already.

Regards,
Tobias


More information about the Dev mailing list