Comment 5 for bug 1744223

Revision history for this message
Hunt Xu (huntxu) wrote :

Hey guys, sorry for the late response.

@yamamoto, it is not about to keep a vpn service without site connections. Remove the vpn service can solve the problem when it would be only used by one site connection, however it is not true when one vpn service would be used by multiple site connections.

Consider the following scenario:
1. I have a router connected to the public network with only an external IPv4 address, an internal subnet is connected to this router.
2. I setup a vpn site connection to connect the subnet to a remote one, say peerA.
3. Now I want to connect the subnet to another peer(peerB) via the public IPv6 network. I can give the router an external IPv6 address, however I can't setup the new site connection with IPv6 peer because the external_v6_ip of the vpn service is empty. The only way now is to delete the site connection to peerA, then delete and recreate the vpn service, then create both site connections.