Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
cilium: ipsec, wildcard out rules and remove localhost rules
Currently, OUT xfrm rules use full (src,dst,spi) tuple. The original thinking on this was that we wanted to ensure matches only on relavent IP addresses. However now both state and policy are further restricted by mark values we can drop the src piece without worrying about having unintended matches. Signed-off-by: John Fastabend <john.fastabend@gmail.com>
- Loading branch information