libreswan / libreswan

libreswan
https://libreswan.org/
Other
853 stars 225 forks source link

implement IKEv2's non-MOBIKE NAT port/address updates #1529

Open cagney opened 10 months ago

cagney commented 10 months ago

The feature was never fully implemented. See #1492 Theory is to narrow it down to only allow port changes not address changes.

cagney commented 10 months ago

According to https://github.com/libreswan/libreswan/issues/1492#issuecomment-1864175953 port-only-updates don't work.

cagney commented 4 months ago

The feature was never fully implemented. See https://github.com/libreswan/libreswan/issues/1492

There's a rumour that the KLIPS module automatically updated the kernel side.

cagney commented 3 months ago

moving back to 5.2; 5.1 will have a flag to restore broken behaviour only