From afeac365fd0a29cbdda312284df0ea877ad1c886 Mon Sep 17 00:00:00 2001 From: Tobias Brunner Date: Fri, 12 Apr 2024 14:01:23 +0200 Subject: [PATCH] swanctl: Document possibility of non-zero base addresses for in-memory pools References strongswan/strongswan#2205 --- src/swanctl/swanctl.opt | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/src/swanctl/swanctl.opt b/src/swanctl/swanctl.opt index d9fd949ed..78256a6af 100644 --- a/src/swanctl/swanctl.opt +++ b/src/swanctl/swanctl.opt @@ -1331,7 +1331,10 @@ pools..addrs = Subnet or range defining addresses allocated in pool. Accepts a single CIDR subnet defining the pool to allocate addresses from or an address range - (-). Pools must be unique and non-overlapping. + (-). If the address in CIDR notation is not the network ID of the + subnet (e.g. 10.1.0.5/24 instead of 10.1.0.0/24), addresses below it won't + be allocated to clients (they could e.g. be assigned manually to internal + hosts like the VPN server itself). Pools must be unique and non-overlapping. pools.. = Comma separated list of additional attributes from type .