Hi All:
Based on example of /etc/ipsec.d/v6neighbor-hole.conf , the traffic of "ICMPv6 
Neighbor Solicitation" or "ICMPv6 Neighbor Solicitation" in encrypted.  Right ? 
So I think "leftprotoport=17/0" means all UDP traffic is NOT protected by 
IPSec. Right? 
But my colleague thinks "leftprotoport=17/0" 
as:===========================================if the protocol is UDP send it 
through the channelwhich means encrypt and send then other party receives and 
decryptsif the protocol is not UDP then cannot use the tunnelso it works as it 
is designed
Is it correct ???
Thanks and regards
Hao Chen 
                                          

_______________________________________________
Swan mailing list
[email protected]
https://lists.libreswan.org/mailman/listinfo/swan                               
          
_______________________________________________
Swan mailing list
[email protected]
https://lists.libreswan.org/mailman/listinfo/swan

Reply via email to