@yamamoto, I am working on this. My idea is to only update the external_v*_ip of vpnservices upon ipsec-site-connection creation/updating/deleting. The external_v*_ip would be None if the vpnservice is not used by any ipsec-site-connections. Thus operations of the router gateway won't be blocked.
@yamamoto, I am working on this. My idea is to only update the external_v*_ip of vpnservices upon ipsec-site- connection creation/ updating/ deleting. The external_v*_ip would be None if the vpnservice is not used by any ipsec-site- connections. Thus operations of the router gateway won't be blocked.