| Commit message (Expand) | Author | Age | Files | Lines |
* | Add inpcb pointer to struct ipsec_ctx_data and pass it to the pfil hook | Andrey V. Elsukov | 2017-07-31 | 1 | -4/+4 |
* | Disable IPsec debugging code by default when IPSEC_DEBUG kernel option | Andrey V. Elsukov | 2017-05-29 | 1 | -3/+3 |
* | Fix possible double releasing for SA reference. | Andrey V. Elsukov | 2017-05-23 | 1 | -2/+0 |
* | Merge projects/ipsec into head/. | Andrey V. Elsukov | 2017-02-06 | 1 | -379/+151 |
* | Remove redundant sanity checks from ipsec[46]_common_input_cb(). | Andrey V. Elsukov | 2016-08-31 | 1 | -16/+0 |
* | Overhaul if_enc(4) and make it loadable in run-time. | Andrey V. Elsukov | 2015-11-25 | 1 | -52/+22 |
* | IPSEC, remove variable argument function its already due. | Ermal Luçi | 2015-07-21 | 1 | -22/+7 |
* | Since PFIL can change mbuf pointer, we should update pointers after | Andrey V. Elsukov | 2015-04-28 | 1 | -0/+1 |
* | Change ipsec_address() and ipsec_logsastr() functions to take two | Andrey V. Elsukov | 2015-04-18 | 1 | -8/+11 |
* | Requeue mbuf via netisr when we use IPSec tunnel mode and IPv6. | Andrey V. Elsukov | 2015-04-18 | 1 | -1/+30 |
* | Fix handling of scoped IPv6 addresses in IPSec code. | Andrey V. Elsukov | 2015-04-18 | 1 | -0/+7 |
* | Remove now unused mtag argument from ipsec*_common_input_cb. | Andrey V. Elsukov | 2014-12-11 | 1 | -23/+8 |
* | Remove route chaching support from ipsec code. It isn't used for some time. | Andrey V. Elsukov | 2014-12-02 | 1 | -1/+0 |
* | Strip IP header only when we act in tunnel mode. | Andrey V. Elsukov | 2014-11-13 | 1 | -29/+30 |
* | Pass mbuf to pfil processing before stripping outer IP header as it | Andrey V. Elsukov | 2014-11-07 | 1 | -17/+6 |
* | When mode isn't explicitly specified (wildcard) and inner protocol isn't | Andrey V. Elsukov | 2014-11-06 | 1 | -1/+10 |
* | Do not strip outer header when operating in transport mode. | Andrey V. Elsukov | 2014-10-02 | 1 | -2/+10 |
* | Mechanically convert to if_inc_counter(). | Gleb Smirnoff | 2014-09-19 | 1 | -4/+4 |
* | Merge 'struct ip6protosw' and 'struct protosw' into one. Now we have | Kevin Lo | 2014-08-08 | 1 | -6/+31 |
* | Fixed IPv4-in-IPv6 and IPv6-in-IPv4 IPsec tunnels. | VANHULLEBUS Yvan | 2014-05-28 | 1 | -47/+89 |
* | Initialize prot variable. | Andrey V. Elsukov | 2013-11-11 | 1 | -0/+1 |
* | The r48589 promised to remove implicit inclusion of if_var.h soon. Prepare | Gleb Smirnoff | 2013-10-26 | 1 | -0/+1 |
* | Use corresponding macros to update statistics for AH, ESP, IPIP, IPCOMP, | Andrey V. Elsukov | 2013-06-20 | 1 | -54/+30 |
* | Use IP6STAT_INC/IP6STAT_DEC macros to update ip6 stats. | Andrey V. Elsukov | 2013-04-09 | 1 | -2/+2 |
* | - Fix one more miss from r241913. | Gleb Smirnoff | 2012-10-23 | 1 | -2/+4 |
* | Merge the projects/pf/head branch, that was worked on for last six months, | Gleb Smirnoff | 2012-09-08 | 1 | -2/+0 |
* | Update packet filter (pf) code to OpenBSD 4.5. | Bjoern A. Zeeb | 2011-06-28 | 1 | -0/+2 |
* | Make IPsec compile without INET adding appropriate #ifdef checks. | Bjoern A. Zeeb | 2011-04-27 | 1 | -0/+2 |
* | Fix typo in comment. | Thomas Quinot | 2010-10-25 | 1 | -1/+1 |
* | MFp4 @178283: | Bjoern A. Zeeb | 2010-05-24 | 1 | -1/+1 |
* | Merge the remainder of kern_vimage.c and vimage.h into vnet.c and | Robert Watson | 2009-08-01 | 1 | -1/+0 |
* | Build on Jeff Roberson's linker-set based dynamic per-CPU allocator | Robert Watson | 2009-07-14 | 1 | -6/+1 |
* | Added support for NAT-Traversal (RFC 3948) in IPsec stack. | VANHULLEBUS Yvan | 2009-06-12 | 1 | -0/+9 |
* | Properly hide IPv4 only variables and functions under #ifdef INET. | Bjoern A. Zeeb | 2009-06-10 | 1 | -0/+2 |
* | Reimplement the netisr framework in order to support parallel netisr | Robert Watson | 2009-06-01 | 1 | -1/+1 |
* | Rather than using hidden includes (with cicular dependencies), | Bjoern A. Zeeb | 2008-12-02 | 1 | -0/+1 |
* | Step 1.5 of importing the network stack virtualization infrastructure | Marko Zec | 2008-10-02 | 1 | -0/+5 |
* | Commit step 1 of the vimage project, (network stack) | Bjoern A. Zeeb | 2008-08-17 | 1 | -57/+58 |
* | Increase statistic counters for enc0 interface when enabled | VANHULLEBUS Yvan | 2008-08-12 | 1 | -0/+11 |
* | In addition to the ipsec_osdep.h removal a week ago, now also eliminate | Bjoern A. Zeeb | 2008-05-24 | 1 | -2/+0 |
* | Add sysctls to if_enc(4) to control whether the firewalls or | Bjoern A. Zeeb | 2007-11-28 | 1 | -2/+21 |
* | Fix for an infinite loop in processing ESP, IPv6 packets. | George V. Neville-Neil | 2007-09-12 | 1 | -4/+17 |
* | Replace hard coded options by their defined PFIL_{IN,OUT} names. | Bjoern A. Zeeb | 2007-07-19 | 1 | -1/+2 |
* | Looking at {ah,esp}_input_cb it seems we might be able to end up | Bjoern A. Zeeb | 2007-06-15 | 1 | -1/+1 |
* | s,#,*, in a multi-line comment. This is C. | Bjoern A. Zeeb | 2007-06-15 | 1 | -1/+1 |
* | Though we are only called for the three security protocols we can | Bjoern A. Zeeb | 2007-06-15 | 1 | -0/+4 |
* | s,#if INET6,#ifdef INET6, | Bjoern A. Zeeb | 2006-12-14 | 1 | -1/+1 |
* | MFp4: 92972, 98913 + one more change | Bjoern A. Zeeb | 2006-12-12 | 1 | -2/+10 |
* | Add a pseudo interface for packet filtering IPSec connections before or after | Andrew Thompson | 2006-06-26 | 1 | -0/+13 |
* | Change '#if INET' and '#if INET6' to '#ifdef INET' and '#ifdef INET6'. | Pawel Jakub Dawidek | 2006-06-04 | 1 | -1/+1 |