Project

General

Profile

Issue #3118

Use throw type routes instead of copying routes into table 220 for passthrough policies

Added by Noel Kuntze about 1 year ago. Updated 7 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
-
Affected version:
5.8.0
Resolution:

Description

Linux has a special route type "throw", which makes the routing engine pretend no matching route was found in the table.
That could be more useful in adding routes for passthrough policies than what strongSwan does right now (basically copying the routes from the main table into table 220).

charon.log (554 KB) charon.log Acompanying log file for https://github.com/strongswan/strongswan/pull/165 Noel Kuntze, 26.02.2020 14:24

Associated revisions

Revision bbedad78
Added by Tobias Brunner 7 months ago

Merge branch 'throw-type-routes'

Implements simpler routes for passthrough policies on Linux, which
basically act as fallbacks on routes in other routing tables. This way
they require less information (e.g. no interface or source IP) and can
be installed earlier and are not affected by updates.

Closes strongswan/strongswan#165.
Fixes #3118.

History

Also available in: Atom PDF