[Swan-dev] Opportunistic IPSec with wide clear policy issue

Paul Wouters paul at nohats.ca
Tue Nov 20 15:42:48 UTC 2018


On Thu, 15 Nov 2018, Kirill Logachev wrote:

> Thank you for the confirmation!
> We were following an example from here: https://libreswan.org/wiki/HOWTO:_Opportunistic_IPsec (3.3 Assign
> networks).

Thanks, I fixed the documentation.

> Without the priority override it defaults to clear for all connections, so priority was just an attempt to
> find a workaround (other than not to specify 0/0)

So not specifying a 0/0 in clear and not using any priority fixed your
issue?

Paul


More information about the Swan-dev mailing list