ipsec: Disable compression in system policy
authorMichael Tremer <michael.tremer@ipfire.org>
Thu, 3 Aug 2017 12:08:04 +0000 (12:08 +0000)
committerMichael Tremer <michael.tremer@ipfire.org>
Thu, 3 Aug 2017 12:09:37 +0000 (12:09 +0000)
Compression in IPsec is slow (strongSwan only supports
DEFLATE) and there are security concerns about it
revealing information about the plaintext.

So for a little gain in bandwith, it does not seem to
be right to take that risk right now.

Signed-off-by: Michael Tremer <michael.tremer@ipfire.org>
config/vpn/security-policies/system