IPv6 Legacy Configuration Examples¶
These example scenarios use the deprecated stroke management interface.
Site-to-Site¶
IPv6 in IPv6 tunnel mode | IKEv1 | IKEv2 |
IPv4 in IPv6 tunnel mode | IKEv1 | IKEv2 |
IPv6 in IPv4 tunnel mode | IKEv1 | IKEv2 |
Host-to-Host¶
IPv6 tunnel mode | IKEv1 | IKEv2 |
IPv6 transport mode | IKEv1 | IKEv2 |
Remote Access¶
RSA authentication with X.509 certificates | IKEv1 | IKEv2 |
PSK authentication with pre-shared keys | IKEv1 | IKEv2 |
IPv6 in IPv4 tunnel mode with virtual IP | IKEv1 | IKEv2 |
Complete List¶
All IPv6 legacy test scenarios
Please be aware that the strongSwan IKE daemon cannot listen on IPv6 link-local addresses (fe80:..). You must assign a site-local, unique-local, or global IPv6 address to the physical network interface first.