[strongSwan] Leftover "block" policy after IPSec connection is terminated

Tobias Brunner tobias at strongswan.org
Tue Aug 18 16:39:32 CEST 2020


Hi Andreas,

> I don't know if this is intended

It is not.  The drop policies should have been removed together with the
CHILD_SA.

> How can I achieve this?

Not sure what causes it exactly, but upgrading should work (those drop
policies were removed with 5.6.2).

Regards,
Tobias


More information about the Users mailing list