What do you suggest? A strongswan-container in router os? It might be doable. Not certain how that things will be with hardware crypto-support, though.
But anyway, we’d really want to run everything on mikrotik. I know things can move slowly with them, and have been festering support about at least updating the documentation regarding this.
It should be fixable for them, it is a shame that in 2024, Ipv6 support for IPv6-clients is a struggle, opnsense/pfsense does this out of the box. But to Mikrotik’s deffence, Windows 10 at least, require a cli-command to force IPv6 trafic through the tunnel in the bult-in ipsec implimentation.
I was vondering if it is posible to somehow specify an IPv6 address on the client config, similar to how Wireguard work. If it is doable at least strongswan-clients could, that could be temporary solution, but I haven’t done any research.
But anyway, we’d really want to run everything on mikrotik. I know things can move slowly with them, and have been festering support about at least updating the documentation regarding this.
It should be fixable for them, it is a shame that in 2024, Ipv6 support for IPv6-clients is a struggle, opnsense/pfsense does this out of the box. But to Mikrotik’s deffence, Windows 10 at least, require a cli-command to force IPv6 trafic through the tunnel in the bult-in ipsec implimentation.
I was vondering if it is posible to somehow specify an IPv6 address on the client config, similar to how Wireguard work. If it is doable at least strongswan-clients could, that could be temporary solution, but I haven’t done any research.
Statistics: Posted by Nightowl82 — Tue Feb 13, 2024 10:05 pm