Allow IPComp on NATed connections, both for IKEv1 and IKEv2

While this was problematic in earlier releases, it seems that it works just
fine the way we handle compression now. So there is no need to disable it over
NATed connections or when using forceencaps.
This commit is contained in:
Martin Willi
2013-06-11 15:54:25 +02:00
parent f5f7053bcd
commit 44d9970f4c
2 changed files with 10 additions and 33 deletions
+10 -26
View File
@@ -774,19 +774,11 @@ METHOD(task_t, build_i, status_t,
if (this->config->use_ipcomp(this->config))
{
if (this->udp)
this->cpi_i = this->child_sa->alloc_cpi(this->child_sa);
if (!this->cpi_i)
{
DBG1(DBG_IKE, "IPComp is not supported if either peer is "
"natted, IPComp disabled");
}
else
{
this->cpi_i = this->child_sa->alloc_cpi(this->child_sa);
if (!this->cpi_i)
{
DBG1(DBG_IKE, "unable to allocate a CPI from kernel, "
"IPComp disabled");
}
DBG1(DBG_IKE, "unable to allocate a CPI from kernel, "
"IPComp disabled");
}
}
@@ -1009,21 +1001,13 @@ METHOD(task_t, process_r, status_t,
if (this->config->use_ipcomp(this->config))
{
if (this->ike_sa->has_condition(this->ike_sa, COND_NAT_ANY))
list = sa_payload->get_ipcomp_proposals(sa_payload,
&this->cpi_i);
if (!list->get_count(list))
{
DBG1(DBG_IKE, "IPComp is not supported if either peer is "
"natted, IPComp disabled");
}
else
{
list = sa_payload->get_ipcomp_proposals(sa_payload,
&this->cpi_i);
if (!list->get_count(list))
{
DBG1(DBG_IKE, "expected IPComp proposal but peer did "
"not send one, IPComp disabled");
this->cpi_i = 0;
}
DBG1(DBG_IKE, "expected IPComp proposal but peer did "
"not send one, IPComp disabled");
this->cpi_i = 0;
}
}
if (!list || !list->get_count(list))
@@ -678,13 +678,6 @@ static void build_payloads(private_child_create_t *this, message_t *message)
static void add_ipcomp_notify(private_child_create_t *this,
message_t *message, u_int8_t ipcomp)
{
if (this->ike_sa->has_condition(this->ike_sa, COND_NAT_ANY))
{
DBG1(DBG_IKE, "IPComp is not supported if either peer is natted, "
"IPComp disabled");
return;
}
this->my_cpi = this->child_sa->alloc_cpi(this->child_sa);
if (this->my_cpi)
{