… | |
… | |
379 | |
379 | |
380 | Sets the rekeying interval in seconds (default: C<3600>). Connections are |
380 | Sets the rekeying interval in seconds (default: C<3600>). Connections are |
381 | reestablished every C<rekey> seconds, making them use a new encryption |
381 | reestablished every C<rekey> seconds, making them use a new encryption |
382 | key. |
382 | key. |
383 | |
383 | |
|
|
384 | =item nfmark = integer |
|
|
385 | |
|
|
386 | This advanced option, when set to a nonzero value (default: C<0>), tries |
|
|
387 | to set the netfilter mark (or fwmark) value on all sockets gvpe uses to |
|
|
388 | send packets. |
|
|
389 | |
|
|
390 | This can be used to make gvpe use a different set of routing rules. For |
|
|
391 | example, on GNU/Linux, the C<if-up> could set C<nfmark> to 1000 and then |
|
|
392 | put all routing rules into table C<99> and then use an ip rule to make |
|
|
393 | gvpe traffic avoid that routing table, in effect routing normal traffic |
|
|
394 | via gvpe and gvpe traffic via the normal system routing tables: |
|
|
395 | |
|
|
396 | ip rule add not fwmark 1000 lookup 99 |
|
|
397 | |
384 | =back |
398 | =back |
385 | |
399 | |
386 | =head2 NODE SPECIFIC SETTINGS |
400 | =head2 NODE SPECIFIC SETTINGS |
387 | |
401 | |
388 | The following settings are node-specific, that is, every node can have |
402 | The following settings are node-specific, that is, every node can have |
… | |
… | |
607 | |
621 | |
608 | The default (or recommended) directory layout for the config directory is: |
622 | The default (or recommended) directory layout for the config directory is: |
609 | |
623 | |
610 | =over 4 |
624 | =over 4 |
611 | |
625 | |
612 | =item X<gvpe.conf> |
626 | =item gvpe.conf |
613 | |
627 | |
614 | The config file. |
628 | The config file. |
615 | |
629 | |
616 | =item X<if-up> |
630 | =item if-up |
617 | |
631 | |
618 | The if-up script |
632 | The if-up script |
619 | |
633 | |
620 | =item X<node-up>, X<node-down> |
634 | =item node-up, node-down |
621 | |
635 | |
622 | If used the node up or node-down scripts. |
636 | If used the node up or node-down scripts. |
623 | |
637 | |
624 | =item X<hostkey> |
638 | =item hostkey |
625 | |
639 | |
626 | The private key (taken from C<hostkeys/nodename>) of the current host. |
640 | The private key (taken from C<hostkeys/nodename>) of the current host. |
627 | |
641 | |
628 | =item X<pubkey/nodename> |
642 | =item pubkey/nodename |
629 | |
643 | |
630 | The public keys of the other nodes, one file per node. |
644 | The public keys of the other nodes, one file per node. |
631 | |
645 | |
632 | =back |
646 | =back |
633 | |
647 | |