charon-nm: Use a different routing table than the regular IKE daemon
If the regular daemon is running, it creates an unconditional routing rule for the routing table. The rule that charon-nm tries to create, which excludes marked IKE/ESP traffic to avoid a routing loop, then can't be installed and we'd end up with said loop. Closes strongswan/strongswan#2230
This commit is contained in:
@@ -205,11 +205,17 @@ int main(int argc, char *argv[])
|
|||||||
/* install routes via XFRM interfaces, if we can use them */
|
/* install routes via XFRM interfaces, if we can use them */
|
||||||
lib->settings->set_default_str(lib->settings,
|
lib->settings->set_default_str(lib->settings,
|
||||||
"charon-nm.plugins.kernel-netlink.install_routes_xfrmi", "yes");
|
"charon-nm.plugins.kernel-netlink.install_routes_xfrmi", "yes");
|
||||||
/* bypass IKE traffic from these routes in case traffic selectors conflict */
|
/* use a separate routing table to avoid conflicts with regular charon */
|
||||||
lib->settings->set_default_str(lib->settings,
|
lib->settings->set_default_str(lib->settings,
|
||||||
"charon-nm.plugins.socket-default.fwmark", "220");
|
"charon-nm.routing_table", "210");
|
||||||
|
/* use the same value as priority (higher than charon's default) */
|
||||||
lib->settings->set_default_str(lib->settings,
|
lib->settings->set_default_str(lib->settings,
|
||||||
"charon-nm.plugins.kernel-netlink.fwmark", "!220");
|
"charon-nm.routing_table_prio", "210");
|
||||||
|
/* bypass IKE/ESP from these routes in case traffic selectors conflict */
|
||||||
|
lib->settings->set_default_str(lib->settings,
|
||||||
|
"charon-nm.plugins.socket-default.fwmark", "210");
|
||||||
|
lib->settings->set_default_str(lib->settings,
|
||||||
|
"charon-nm.plugins.kernel-netlink.fwmark", "!210");
|
||||||
|
|
||||||
DBG1(DBG_DMN, "Starting charon NetworkManager backend (strongSwan "VERSION")");
|
DBG1(DBG_DMN, "Starting charon NetworkManager backend (strongSwan "VERSION")");
|
||||||
if (lib->integrity)
|
if (lib->integrity)
|
||||||
|
|||||||
@@ -912,10 +912,9 @@ static gboolean connect_(NMVpnServicePlugin *plugin, NMConnection *connection,
|
|||||||
if (priv->xfrmi_id)
|
if (priv->xfrmi_id)
|
||||||
{ /* set the same mark as for IKE packets on the ESP packets so no routing
|
{ /* set the same mark as for IKE packets on the ESP packets so no routing
|
||||||
* loop is created if the TS covers the VPN server's IP */
|
* loop is created if the TS covers the VPN server's IP */
|
||||||
child.set_mark_out = (mark_t){
|
mark_from_string(lib->settings->get_str(lib->settings,
|
||||||
.value = 220,
|
"charon-nm.plugins.socket-default.fwmark", NULL),
|
||||||
.mask = 0xffffffff,
|
MARK_OP_NONE, &child.set_mark_out);
|
||||||
};
|
|
||||||
child.if_id_in = child.if_id_out = priv->xfrmi_id;
|
child.if_id_in = child.if_id_out = priv->xfrmi_id;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user