[strongSwan] Workaround for Mac Duplication Issue

2020-09-30 Thread brian.g.colby
Hello, I am encountering a weird issue on macOS where, after the system wakes up from sleep or changes networks, a duplicate connection shows up on the endpoint. Then, every 120s or so, it switches to the other connection, briefly interrupting the user's session. When I run swanctl --list-sas

[strongSwan] Does Strongswan work with an IP address not associated with an interface?

2020-09-30 Thread Leroy Tennison
I am trying to use Strongswan with an interface which exists only in firewall rules (and the destination/source IP addresses of packets). This hasn't been a problem in other situations but, when I attempt it with Strongswan, I don't see any traffic at all in a packet trace (and I have used the

Re: [strongSwan] Restricting protocol and port numbers question

2020-09-30 Thread Tobias Brunner
Hi Rajiv, > 1. with policies based on ports/protocols used, Would the routes need to > be added still, if we say disable use of table 220 by applying the > option "install_routes=no" in charon.conf??? As I said, no routes are installed for policies with port/protocol anyway. So why disable route