updated API doc for socket.h
[strongswan.git] / src / charon / config / child_cfg.h
index 228f0d8..ddd4807 100644 (file)
@@ -25,7 +25,6 @@
 #ifndef CHILD_CFG_H_
 #define CHILD_CFG_H_
 
-typedef enum mode_t mode_t;
 typedef enum action_t action_t;
 typedef enum ipcomp_transform_t ipcomp_transform_t;
 typedef struct child_cfg_t child_cfg_t;
@@ -33,25 +32,7 @@ typedef struct child_cfg_t child_cfg_t;
 #include <library.h>
 #include <config/proposal.h>
 #include <config/traffic_selector.h>
-
-/**
- * Mode of an CHILD_SA.
- *
- * These are equal to those defined in XFRM, so don't change.
- */
-enum mode_t {
-       /** transport mode, no inner address */
-       MODE_TRANSPORT = 0,
-       /** tunnel mode, inner and outer addresses */
-       MODE_TUNNEL = 1,
-       /** BEET mode, tunnel mode but fixed, bound inner addresses */
-       MODE_BEET = 4,
-};
-
-/**
- * enum names for mode_t.
- */
-extern enum_name_t *mode_names;
+#include <kernel/kernel_ipsec.h>
 
 /**
  * Action to take when DPD detected/connection gets closed by peer.
@@ -173,6 +154,17 @@ struct child_cfg_t {
                                                                                        host_t *host);
 
        /**
+        * Checks [single] traffic selectors for equality 
+        *
+        * @param local                 TRUE for TS on local side, FALSE for remote
+        * @param ts                    list with single traffic selector to compare with
+        * @param host                  address to use for narrowing "dynamic" TS', or NULL
+        * @return                              TRUE if TS are equal, FALSE otherwise
+        */ 
+       bool (*equal_traffic_selectors)(child_cfg_t *this, bool local,
+                                                                  linked_list_t *ts_list, host_t *host);
+
+       /**
         * Get the updown script to run for the CHILD_SA.
         * 
         * @return                              path to updown script
@@ -208,7 +200,7 @@ struct child_cfg_t {
         * 
         * @return                              ipsec mode
         */
-       mode_t (*get_mode) (child_cfg_t *this);
+       ipsec_mode_t (*get_mode) (child_cfg_t *this);
        
        /**
         * Action to take on DPD.
@@ -238,6 +230,31 @@ struct child_cfg_t {
         *                                              FALSE, otherwise
         */
        bool (*use_ipcomp)(child_cfg_t *this);
+
+       /**
+        * Sets two options needed for Mobile IPv6 interoperability
+        * 
+        * @proxy_mode                  use IPsec transport proxy mode (default FALSE)
+        * @install_policy              install IPsec kernel policies (default TRUE)
+        */
+       void (*set_mipv6_options)(child_cfg_t *this, bool proxy_mod,
+                                                                                                bool install_policy);
+
+       /**
+        * Check whether IPsec transport SA should be set up in proxy mode
+        * 
+        * @return                              TRUE, if proxy mode should be used
+        *                                              FALSE, otherwise
+        */
+       bool (*use_proxy_mode)(child_cfg_t *this);
+       
+       /**
+        * Check whether IPsec policies should be installed in the kernel
+        * 
+        * @return                              TRUE, if IPsec kernel policies should be installed
+        *                                              FALSE, otherwise
+        */
+       bool (*install_policy)(child_cfg_t *this);
        
        /**
         * Increase the reference count.
@@ -279,8 +296,7 @@ struct child_cfg_t {
  */
 child_cfg_t *child_cfg_create(char *name, u_int32_t lifetime,
                                                          u_int32_t rekeytime, u_int32_t jitter,
-                                                         char *updown, bool hostaccess, mode_t mode,
-                                                         action_t dpd_action, action_t close_action,
-                                                         bool ipcomp);
+                                                         char *updown, bool hostaccess, ipsec_mode_t mode,
+                                                         action_t dpd_action, action_t close_action, bool ipcomp);
 
 #endif /* CHILD_CFG_H_ @} */