[strongSwan] Redirect 0.0.0.0/0 into tunnel for local side

Kevin Olbrich ko at sv01.de
Sat Jul 21 09:03:47 CEST 2018


Hi!

During updates today (F28) I broke my strongswan setup.
The upgraded server has a VPN connection to another office and it's purpose
is to route all traffic including internet.

I set "rightsubnet=0.0.0.0/0" which was working perfectly fine but after
todays update, strongswan edits the default route of the main kernel table
to ipsec0 which effectivly cuts of all management access.

Also I set charon.install_routes to no but it still modifies the route. How
can I completly disable route modification? I am setting the rules
(shorewall providers) myself.

Kevin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.strongswan.org/pipermail/users/attachments/20180721/2fae30b7/attachment.html>


More information about the Users mailing list