services.strongswan-swanctl.swanctl.connections.<name>.children.<name>.hw_offload
Enable hardware offload for this CHILD_SA, if supported by the IPsec
implementation. The values crypto or packet enforce crypto or full
packet offloading and the installation will fail if the selected mode is not
supported by either kernel or device. On Linux, packet also offloads
policies, including trap policies. The value auto enables full packet
or crypto offloading, if either is supported, but the installation does not
fail otherwise.
StrongSwan default: "no"
- Type
null or one of "yes", "no", "auto", "crypto", "packet"- Default
null- Declared
- <nixpkgs/nixos/modules/services/networking/strongswan-swanctl/module.nix>