From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael Tremer To: development@lists.ipfire.org Subject: Re: AW: IPsec: Include ipsec.user.conf at the bottom Date: Tue, 19 May 2015 17:34:38 +0200 Message-ID: <1432049678.16602.48.camel@ipfire.org> In-Reply-To: MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============2224314751202626562==" List-Id: --===============2224314751202626562== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 8bit Yeah I thought that this was going in some of these directions where you want to add really bad configuration directives like rekey=no. We will discuss that in the other thread on this list though... I generally oppose having too many "hidden" include files that can be used to overwrite the basic configuration. They often give us a headache when we touch things because eventually we will break some of those manual settings. We keep telling ourselves that this is fine because we never said that we supported them any way. But that is not really a valid point. The better option should be to not need those files. -Michael On Tue, 2015-05-19 at 17:28 +0200, Larsen wrote: > Just stumbled across this in vpnmain.cgi: > "/etc/ipsec.user-post.conf" > > When this file exists, it will be included. So apparently, we were using > the wrong file (or the documentation is missing that - I donĀ“t know where > my co-worker got it from). > > > Lars > > > > On Tue, 19 May 2015 17:07:41 +0200, Heribert Schorn > wrote: > > > Hi, > > > > I agree withe Larsen suggestions to have the include als at the bottom. > > With the include stetment on the top the seteetings of ipsec.user.conf > > are overwritten and the connection e.g. to IOS or Android will not work > > following the proposal in the wiki or the forum. > > > > regards > > Heribert --===============2224314751202626562== Content-Type: application/pgp-signature Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="signature.asc" MIME-Version: 1.0 LS0tLS1CRUdJTiBQR1AgU0lHTkFUVVJFLS0tLS0KVmVyc2lvbjogR251UEcgdjIKCmlRSWNCQUFC Q2dBR0JRSlZXMWdSQUFvSkVJQjU4UDl2a0FrSEg2Z1AvM0Y2NC90TzVkbnhVOFhSVDg2dnE2Nk4K VG1GdHlMbTNrT2dha0NXdmVJK1YwRVF6algyS2IwdXRPUWFOYkcxbG8xTWUwRWxwWXQrOGR6T3Zi TjBvdU9Hdwphd1BuNFpOa05ERHgwSUFvL0pFMVphTnZWbHI5Tks5Yy8xUWNHNHUxV0dRY1hudDBT dWxRYnkrQ1hGdk50K0cxCkU2NXh0WE16T05EODNQOUwyUGcvbDBZTVJNay8yeFRuOUYyaUsyenVv aU5SMjNrV25IUGNxQS9pbUFQcGlyRSsKam5JdGkvaGRUbWJVUDhQVGNRSlh4NzFPRDdIZ3gvNHFP VjFrdmdvYW9ZeFBPOTFlbFVHOFFLTDk4cHMvLzlxSQpxSVAxZUgvVE9Tbnc3c1doZzFNUlUzNmd3 SUNqV3VNbS9CL29xbzdOQXM1aVF2RnhlbDZLcFRuQnhWYXcybkdsCmQxOSt0VTNLRGZvaVFFUVh1 Q1E4TytnV1ZlNTlwUHVQMTBTUTR1VkVSUjAzNXgva0xmVGZ3YWpMYmN4a3Y1bksKL1R5MzBFNzFW a0xVTW9lbEs1SEd1dldDdUw5TG5uY09ZWHhFcXQ3OFZqV0laWi9IeUp5NFB6aGMyM1VKN3ZYawoz am9LMXhyZStueXYwVmQ3VDY0WVRlSytjelozOWhic0kvK2FDbG5iYmVFbFMzZkxCWDJzdklwMHNR aE9rK1JoCkEzdm41TDIxR0pISmtDNEtMdmpQT3NpRkE4YjU4c2xuMFBDdm9JYUtNQ1RubmY1YkRT bUliQW9DS1VMR0hjblQKMC8zOHpmYVV2NHF0NmtsRi8rVHBZZ21KZDdLdVA3NzNvUE9rMnlxVXRE OGVJbW9hdlllTGJrU0VSdkZhcys2Wgp1VE9vYkRaMmpXVzNkTnFYWFNiQwo9dlZUUQotLS0tLUVO RCBQR1AgU0lHTkFUVVJFLS0tLS0K --===============2224314751202626562==--