Page MenuHomePhabricator

Add support for IPSec XFRM interfaces
Open, Requires assessmentPublicFEATURE REQUEST

Description

This seems to be a solution for VTI interfaces not supporting IPv6. (or IPv4 on vti6 interfaces)

https://wiki.strongswan.org/projects/strongswan/wiki/RouteBasedVPN#XFRM-Interfaces-on-Linux
https://lwn.net/Articles/757391/
https://wiki.strongswan.org/issues/2845

I currently have vti tunnels to multiple sites. Each site has an additional sit tunnel within the vti tunnel for ipv6 support. It would be very nice to get rid of that overhead.

Details

Difficulty level
Unknown (require assessment)
Version
-
Why the issue appeared?
Will be filled on close

Event Timeline

mb300sd created this task.Jun 16 2019, 10:07 PM
pasik added a subscriber: pasik.Jun 18 2019, 8:27 AM