[Swan-dev] [Swan] Cisco IOS IPv6 Transport with IKEv2 to Libreswan

Paul Wouters paul at nohats.ca
Mon Jul 2 15:27:03 UTC 2018


On Sat, 30 Jun 2018, Reuben Farrelly wrote:

> I didn't receive any response to my last email and I've been looking again at 
> this today, still with no luck...but I have more ideas:

Sorry, we have been busy and there is the upcoming NetDev and IETF
meetings too and all.

> Question: I am not seeing a VTI come up at all when I use IPv6 transport.

Yeah I think our updown script needs to be enhanced to support IPv6 VTI.
Maybe Tuomo can pick that up :)

>
> The Cisco thinks everything is up and running just fine, and it transmits 
> packets over the tunnel, but never receives a response.

You could try and manually add the VTI device to confirm, using the ip
tunnel command.

> I also don't know what the kernel requirements are in terms of IPv6 and 
> kernel/interface modules either (perhaps these could be added to the 
> documentation for those not using Fedora/RHEL/Centos?)

I don't think you need any other kernel modules for this.

Paul


More information about the Swan-dev mailing list