[Swan-dev] XFRM policies enhancements

Amir Naftali amir at fortycloud.com
Sun Nov 15 12:50:17 UTC 2015


Hi All,

We're  interested in extending some of the libreswan/pluto XFRM policies
(NETKEY only at this point) to support "mark/mask"  and dev.

the relevant reference from the xfrm man page...

ip xfrm policy { add | update } SELECTOR dir DIR [ ctx CTX ] [ mark MARK [ mask
MASK ] ] [ index INDEX ] [ ptype PTYPE ] [ action ACTION ] [ priority
PRIORITY ] [ flag FLAG-LIST ] [ LIMIT-LIST ] [ TMPL-LIST ]

SELECTOR := [ src ADDR[/PLEN] ] [ dst ADDR[/PLEN] ] [ dev DEV ] [ UPSPEC ]


Is there any work that was already done in this area that we can use? any
existing design thoughts?

What's the process we should follow for code contribution?


Amir

*Amir Naftali* | *CTO and Co-Founder | +972 54 497 2622*

<http://www.fortycloud.com/?utm_campaign=amir_email&utm_medium=email&utm_source=signature&utm_content=link&utm_term=amir_sig>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.libreswan.org/pipermail/swan-dev/attachments/20151115/35d872b2/attachment.html>


More information about the Swan-dev mailing list