This seems to be a solution for VTI interfaces not supporting IPv6. (or IPv4 on vti6 interfaces)
https://wiki.strongswan.org/projects/strongswan/wiki/RouteBasedVPN#XFRM-Interfaces-on-Linux
https://lwn.net/Articles/757391/
https://wiki.strongswan.org/issues/2845
I currently have vti tunnels to multiple sites. Each site has an additional sit tunnel within the vti tunnel for ipv6 support. It would be very nice to get rid of that overhead.