#! /bin/sh /usr/share/dpatch/dpatch-run ## /tmp/programs--_confread--ipsec.conf.5-linebreak.patch.dpatch by Harald Jenny ## ## All lines beginning with `## DP:' are a description of the patch. ## DP: fdebd ## DP: Author: Harald Jenny ## DP: ## DP: ## DP: fix manpage to allow line break @DPATCH@ diff --git a/programs/_confread/ipsec.conf.5 b/programs/_confread/ipsec.conf.5 index 0a6f41b..fd22a78 100644 --- a/programs/_confread/ipsec.conf.5 +++ b/programs/_confread/ipsec.conf.5 @@ -1015,7 +1015,7 @@ contains the networks that are allowed as subnet= for the remote client\&. In ot and IPv6 is denoted as \fI%v6:aaaa::bbbb:cccc:dddd:eeee/mm\fR\&. One can exclude subnets by using the \fB!\fR\&. For example, if the VPN server is giving access to 192\&.168\&.1\&.0/24, this option should be set to: -\fIvirtual_private=%v4:10\&.0\&.0\&.0/8,%v4:192\&.168\&.0\&.0/16,%v4:172\&.16\&.0\&.0/12,%v4:!192\&.168\&.1\&.0/24\fR\&. This parameter is only needed on the server side and not on the client side that resides behind the NAT router, as the client will just use its IP address for the inner IP setting\&. This parameter may eventually become per\-connection\&. See also +\fIvirtual_private=\:%v4:10\&.0\&.0\&.0/8,\:%v4:192\&.168\&.0\&.0/16,\:%v4:172\&.16\&.0\&.0/12,\:%v4:!192\&.168\&.1\&.0/24\fR\&. This parameter is only needed on the server side and not on the client side that resides behind the NAT router, as the client will just use its IP address for the inner IP setting\&. This parameter may eventually become per\-connection\&. See also \fBleftsubnet=\fR .sp Note: It seems that T\-Mobile in the US and Rogers/Fido in Canada have started using 25\&.0\&.0\&.0/8 as their pre\-NAT range\&. This range technically belows to the Defence Interoperable Network Services Authority (DINSA), an agency of the Ministry of Defence of the United Kingdom\&. The network range seems to not have been announced for decades, which is probably why these organisasions "borrowed" this range\&. To support roadwarriors on these 3G networks, you might have to add it to the virtual_private= line\&.