Search K
Appearance
Appearance
strongSwan 组件名称为 strongswan. 相关内核选项为
# Networking support
# -> Networking options
# -> TCP/IP networking
# -> IP: ESP transformation
CONFIG_INET_ESP=y
# Networking support
# -> Networking options
# -> TCP/IP networking
# -> The IPv6 protocol
# -> IPv6: ESP transformation
CONFIG_INET6_ESP=y
# Networking support
# -> Networking options
# -> Transformation user configuration interface
CONFIG_XFRM_USER=y
# Networking support
# -> Networking options
# -> Transformation virtual interface
CONFIG_XFRM_INTERFACE=y
# Networking support
# -> Networking options
# -> Network packet filtering framework (Netfilter)
# -> Core Netfilter Configuration
# -> Netfilter Xtables support (required for ip_tables)
# -> IPsec "policy" match support
CONFIG_NETFILTER_XT_MATCH_POLICY=y检查工具为
#!/opt/sum/bin/bash
source ./kernel_config_utils.sh
source ./net_utils.sh
strongswan_check() {
local is_error
is_error="false"
if ! kernel_config_check CONFIG_INET_ESP esp4; then
is_error=true
fi
if ! kernel_config_check CONFIG_INET6_ESP esp6; then
is_error=true
fi
if ! kernel_config_check CONFIG_XFRM_USER xfrm_user; then
is_error=true
fi
if ! kernel_config_check CONFIG_XFRM_INTERFACE xfrm_interface; then
is_error=true
fi
if [ "$(kernel_version_cmp "$KERNEL_VERSION" "v4.2")" -lt "0" ]; then
if ! kernel_config_check CONFIG_INET_XFRM_MODE_TRANSPORT xfrm4_mode_transport; then
is_error=true
fi
if ! kernel_config_check CONFIG_INET_XFRM_MODE_TUNNEL xfrm4_mode_tunnel; then
is_error=true
fi
if ! kernel_config_check CONFIG_INET_XFRM_MODE_BEET xfrm4_mode_beet; then
is_error=true
fi
fi
if ! kernel_config_check CONFIG_NETFILTER_XT_MATCH_POLICY xt_policy; then
is_error=true
fi
if [ "$is_error" == "true" ]; then
return 1
fi
if ! iptables_rule_check mangle PREROUTING -m policy --dir in; then
return 1
fi
return 0
}