[strongSwan] Avoiding adding IP to loopback interface

Tobias Brunner tobias at strongswan.org
Wed Oct 3 17:28:20 CEST 2018


Hi Simon,

> Strongswan (well, I'm pretty sure it's Strongswan) adds a /32 IP to my
> loopback interface when bringing up the connection.

I don't think it is.  strongSwan only adds virtual IPs (assigned from
the other peer, and since you don't request one with leftsourceip, there
won't be any) to local interfaces, and to `lo` only if explicitly
configured to do so (via charon.install_virtual_ip_on).  There will also
be a log message if an IP address is installed.

Regards,
Tobias


More information about the Users mailing list