[strongSwan] IPv6 source address choice of charon-nm

Kajetan Staszkiewicz vegeta at tuxpowered.net
Mon Jul 6 17:52:16 CEST 2020


On 11.06.20 11:44, Tobias Brunner wrote:
> Hi Kajetan,
> 
>> So why is charon-nm choosing different source address than every other
>> program? Can I somehow influence it?
> 
> Try enabling charon-nm.prefer_temporary_addrs in strongswan.conf.  I
> guess it could even make sense to change that default for the NM backend.
Enabling this option causes no route to be installed in table 220 and
thus no traffic routed over VPN for IPv6. The IP address oferred by VPN
server gets assigned on primary interface, though.

-- 
| pozdrawiam / greetings | Powered by macOS, Debian and FreeBSD |
|  Kajetan Staszkiewicz  |  www: http://vegeta.tuxpowered.net   |
`------------------------^--------------------------------------'

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 195 bytes
Desc: OpenPGP digital signature
URL: <http://lists.strongswan.org/pipermail/users/attachments/20200706/7650ac1a/attachment.sig>


More information about the Users mailing list