[strongSwan] virtual IP ranges overlapping with ISP or Wifi ranges

Daniel Pocock daniel at pocock.com.au
Thu Jun 27 11:13:11 CEST 2013

I understand that strongSwan is able to hand out virtual IPs, typically
for road-warriors

If the virtual IPs are from the range, it would appear
there is a high risk that when a roadwarrior is on a home wifi with the
same subnet there will be confusion, so I would assume
those addresses should be avoided as virtual IPs.

Many mobile carriers use 10.x.x.x NAT addresses for their customers. 
With the rise of mobile devices (both USB modems and smartphones running
IPsec) it is becoming very common for users to have a 10.x.x.x/X address
on their roadwarrior device.  Does this mean that virtual IP setups
should avoid that whole 10.x/8 network now?  Can anyone make any
practical comments on how to choose virtual IPs?  IPv6 is obviously one
good solution, but not everybody is ready for that.

