Allow IPv4 over IPv6 IPsec and vice versa
Closed, ResolvedPublicENHANCEMENT


Right now our CLI disallows using IPv4 internal networks over IPv6 IPsec tunnels and vice versa.

It's an artificial limitation introduced back in Vyatta Core times:

As far as I remember, we've added that restriction because we didn't have QA personnel time allocated for testing it, and we didn't want to roll out a potentially broken feature.
So, we chose to disable that path until someone comes asking for it, and until recently no one asked.

Now it's time to verify that it works with up to date StrongSWAN and officially allow those configurations.


Difficulty level
Unknown (require assessment)
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Perfectly compatible

