Comment 21 for bug 872824

Revision history for this message
Martin Willi (martinwilli) wrote :

> Shouldn't a VPN plugin be able to simply pass, for example, the actual device over which the VPN connection is established as TUNDEV rather than a tun device?

No, this doesn't seem to work, as NM does some changes to that interface, breaking things completely.

Passing "lo" seems to work, though. You may try the attached (second) patch (against strongSwan itself, version 4.5.2). The first patch fixes another issue that we fixed some time ago upstream.

While this might work as a work-around for now, I don't think this is an ideal solution. For the long term, we have our own tundev based backend in the pipeline that should work much better with NM.