libxt_policy.man revision 510aef98a56cdbfdb147f78b05d7554bb91770a9
1This modules matches the policy used by IPsec for handling a packet.
2.TP
3\fB--dir\fP {\fBin\fP|\fBout\fP}
4Used to select whether to match the policy used for decapsulation or the
5policy that will be used for encapsulation.
6.B in
7is valid in the
8.B PREROUTING, INPUT and FORWARD
9chains,
10.B out
11is valid in the
12.B POSTROUTING, OUTPUT and FORWARD
13chains.
14.TP
15\fB--pol\fP {\fBnone\fP|\fBipsec\fP}
16Matches if the packet is subject to IPsec processing.
17.TP
18.BI "--strict"
19Selects whether to match the exact policy or match if any rule of
20the policy matches the given policy.
21.TP
22.BI "--reqid " "id"
23Matches the reqid of the policy rule. The reqid can be specified with
24.B setkey(8)
25using
26.B unique:id
27as level.
28.TP
29.BI "--spi " "spi"
30Matches the SPI of the SA.
31.TP
32\fB--proto\fP {\fBah\fP|\fBesp\fP|\fBipcomp\fP}
33Matches the encapsulation protocol.
34.TP
35\fB--mode\fP {\fBtunnel\fP|\fBtransport\fP}
36Matches the encapsulation mode.
37.TP
38\fB--tunnel-src\fP \fIaddr\fP[\fB/\fP\fImask\fP]
39Matches the source end-point address of a tunnel mode SA.
40Only valid with \fB--mode tunnel\fP.
41.TP
42\fB--tunnel-dst\fP \fIaddr\fP[\fB/\fP\fImask\fP]
43Matches the destination end-point address of a tunnel mode SA.
44Only valid with \fB--mode tunnel\fP.
45.TP
46.BI "--next"
47Start the next element in the policy specification. Can only be used with
48\fB--strict\fP.
49