[strongSwan] migration from StrongSwan 5.1.2 to 5.3.2

Noel Kuntze noel at familie-kuntze.de
Fri Sep 4 20:31:05 CEST 2015


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

It's not about politics or preference.
The problem with ifconfig is that it shows secondary addresses as aliases of the interface, which they are not.
I've helped people in #netfilter, that wrote iptables rules with aliases as input interfaces and wondered why it didn't work.
The problem with route is that it cannot show other routing tables or policy based routing.
strongSwan uses both. It installs "virtual" IPs on interfaces and it uses policy based routing to handle routing.
This makes those tools greatly unsuited for working with strongSwan.
- -- 

Mit freundlichen Grüßen/Kind Regards,
Noel Kuntze

GPG Key ID: 0x63EC6658
Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F 63EC 6658

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJV6eNpAAoJEDg5KY9j7GZYAk8P/RcRNYOyVT7BXcau9FMbjNTo
IIQiO35VtyiDOGrm25gVJS4tu7+dLWFf+WsultGLQ6FLvMgrDx8k//M/txDJT49z
IeZ3O6tIg6qHJaS20bvf0g6rgN9BlGaK4NB/OcAxeXPkRELJCDnVl+zWUuQzhWax
oEu15d30Nw7YAnE4NZ6r20lFhOYPe0ZB6dEyVx3JjKgmI0SMvVeCynkwEnZ+goYz
pzTNFWKljPlen7ROP9incpNsDtw/30EIWwgbxIOKWfljADBuvGU39EeTKhSpqqJ6
k/iIUuut0f+MjZLpJ98mirooQu5zdyIe3qSPkkRwI+gQD5p8nV30xz/gMzD7/hQB
nIgdy6VhzluBeBlE+KeL+0rTnw+fZI+5u6ftlo0xCLyrzfybQdC3Mc2HTn9uatiA
47CJ7+eNXeHhgFiR1G9lFn9CkoeI6N8QG9Y8pe71vuu+Lw2UP9AqrdKBNEgats3y
IX3ryPifl8dXkgIkDWzTGe33giZgQaNyWOSCjuwOmVCceRGXiAkM+yQWHGDGv35l
p5HOCcyhOab/aDKNy7eltJtqRctyIdQqMd1XFvpVTGGcgCt8sM9GWrAZPCIMkGYK
ypf91GzDKVuBhClMuOzStjrGrVr9LyyMc4hSrFdyWPu27I5j66hKE6NjQcRvCrSh
Y9Fl3Gf5XnG/VUhDe5i7
=qiGC
-----END PGP SIGNATURE-----



More information about the Users mailing list