Re: IPv6 in network-manager-openvpn



On Mon, 2013-08-26 at 19:01 +0200, Tore Anderson wrote:
* Dan Williams

On Thu, 2013-08-22 at 21:39 +0200, Nicolas Iooss wrote:
 Your patch fixed the segmentation fault but now NetworkManager sets up a
default route via the VPN even if the OpenVPN server has not pushed any.

Unfortunately we cannot rely on administrators always pushing a default
route if the VPN can actually route all traffic.

Nor can you rely on the VPN always being able to route all traffic...

The assumption here is on the side of security, that it's better to send
all traffic to the VPN and fail, than it is to send your traffic over
un-encrypted links when a VPN is supposed to be active and you think
things are encrypted.

Dan

The problem you're going to run into is that the NM-openvpn plugin
doesn't yet support IPv6, because last time some patches got proposed,
openvpn didn't have full IPv6 support and didn't pass back the necessary
stuff to the helper script :(  That may have changed?

Most definitely! More info here:
https://bugzilla.gnome.org/show_bug.cgi?id=682620#c1

BTW: When I tested Nicolas' patches I did so using the standard F19
OpenVPN RPM. It Works(tm)!

Tore




[Date Prev][Date Next]   [Thread Prev][Thread Next]   [Thread Index] [Date Index] [Author Index]