Replies: 27 comments
-
|
I'm wondering why on my VPS, unlike my physical servers, I don't have the same routes in strongSwan's 220 table; I don't have the " And so, it selects the wrong IPv6 address. And so, it selects the wrong IPv6 Address. Before "2025-02-14 (route table 220 VPS-DE)" on the VPS I had my " Example: On VPSs OVH Cloud :→ OK → KO → OK Above : I need to switch the IPv6 GUA to obsolete " RFC 6724: Default Address Selection for Internet Protocol version 6 (IPv6) of Stéphane Bortzmeyer (French Page). Below : And : → KO → OK → KO AND yet : for "
And for "
We can see the same thing in the routing tables of vps-de ? Before "2025-02-14 (route table 220 VPS-DE)" on the VPS I had my " Where is the router, the gateway ?? Don't tell me these are "network card aliases" of a card - their network configuration for our VPS ? On SRVs OVH Cloud :Everything works normally without going obsolete, and the routes are available in table 220. → OK → OK → OK The router, the gateway ! OK on OVH Cloud dedicated servers. What do you think ? Thanks. And for example : Capture d'écran 2025-03-21 105832 - Apache2 Load Balancer - VPS-DE to Backends SRV-CA and SRV-FR - down Cf : Apache2 / Reverse Proxy Guide And PAF - 503 Service Unavailable Note of Me 2025/03/25 : I believe that the error comes from my configuration on VPS-UK and VPS-DE; It must be the variable " And, well no ! Here, I ping from the German VPS my smartphone (which is connected to the VPN on the Canadian server, in a 4G cellular network from France) but I do not understand this traceroute - my "bond points" are identifiable - I had to go through one or two Sattelite or 3 or 4 * * * * ; I don't know how 🫶 The 4 ping dump from VPS-DE : And yet !!!!!!The traceroute arrives well in Canada (" On the "bond point 2" I should see my IP " The problem is in the Strongswan routing table 220 ; Really ; Does it seem to me !!! To be not well, there is no " I don't know ! I have another info from my ULA network; The traceroute goes to my bridge " I do not know where the problem comes from - it is surely at OVH VPS - And Yet !!!! The 4 ping dump from home : I had already done tests ; once ; here. Example alias linux : Or it is a problem on the configuration of my network - that must be that - really, I do not find "where is the error ?". 😵💫🫤 I have another info; From a "NS3" container of the VPS-DE network has been working for " 🥸 Well, it works now !! Good !!! So now I'm going to try reactivating my GUA in lifetime mode forever. Instead of the deprecated "preferred_lft 0sec" mode. → OK → OK → KO Above with the 2 IPv6 addresses "GUA" and "SLA" on the interface connected in " If I set the GUA to "obsolete", I have access to the SLA network " So, problem of departure on VPSs - On the SRVs I have access to all networks - GUA and ULA and SLA. For example, above, I tell the router VPS (a single ULA IP address " For the SLA network " And for the Internet GUA network, it should logically exit via the default gateway, without obsoleting it. 😟 🛠 GestióIP : IPv4/IPv6 subnet calculator Example : I access my NS3 service (in deprecated GUA) - And I receive the response. Off-Topic - Click to expand : DNS64I'm not familiar with the " How and with which transform command can I create the illusion that an IPv4 resource can be accessed with an IPv6 address, DNS64. We find the " Preference IPs (prefixpolicies) in Windows - (example) Show IP preference order (policy) under Linux - CF : configuration of " Off-Topic - Click to expand : ORCHIDv2
It might be related... heh heh heh. Or not, because no problem on SRV-CA and same IP prefix configuration. Romain. |
Beta Was this translation helpful? Give feedback.
-
|
Note strongSwan Docs : IPv6 and the Neighbor Discovery Protocol Overview When using IPv6 a potential pitfall is that traffic selectors of established tunnels might also cover packets used by the Neighbor Discovery Protocol (NDP), in particular if all traffic is tunneled (traffic selector is Configure " Configure " Note Redirect (R): IANA : Internet Control Message Protocol version 6 (ICMPv6) Parameters Last Updated : 2024-12-20 - Crypto-Types Reference : [RFC8928]. IANA : IPv6 Multicast Address Space Registry - Variable Scope Multicast Addresses : Network Time Protocol (NTP) Reference [RFC5905]
IPv6 Addressing Architecture - 2.7. Multicast AddressesAn IPv6 multicast address is an identifier for a group of interfaces (typically on different nodes). An interface may belong to any number of multicast groups. Multicast addresses have the following format :
binary 11111111 at the start of the address identifies the address as being a multicast address.
The high-order flag is reserved, and must be initialized to 0.
scop is a 4-bit multicast scope value used to limit the scope of the multicast group. The values are as follows : Important
The "meaning" of a permanently-assigned multicast address is independent of the scope value. For example, if the "NTP servers group" is assigned a permanent multicast address with a group ID of 101 (hex), then FF01:0:0:0:0:0:0:101 means all NTP (Network Time Protocol) servers on the same interface (i.e., the same node) as the sender. Non-permanently-assigned multicast addresses are meaningful only within a given scope. For example, a group identified by the non-permanent, site-local multicast address Routers must not forward any multicast packets beyond of the scope indicated by the scop field in the destination multicast address. Nodes must not originate a packet to a multicast address whose scop field contains the reserved value IPv6 Addressing Architecture - 2.7.1. Pre-Defined Multicast AddressesThe following well-known multicast addresses are pre-defined. The group IDs defined in this section are defined for explicit scope values. Use of these group IDs for any other scope values, with the T flag equal to 0, is not allowed.
The above multicast addresses are reserved and shall never be assigned to any multicast group.
The above multicast addresses identify the group of all IPv6 nodes, within scope 1 (interface-local) or 2 (link-local).
The above multicast addresses identify the group of all IPv6 routers, within scope 1 (interface-local), 2 (link-local), or 5 (site-local).
Solicited-Node multicast address are computed as a function of a node's unicast and anycast addresses. A Solicited-Node multicast address is formed by taking the low-order 24 bits of an address (unicast or anycast) and appending those bits to the prefix "FF02:0:0:0:0:1:FF00::/104" resulting in a multicast address in the range range "FF02:0:0:0:0:1:FF00:0000" to "FF02:0:0:0:0:1:FFFF:FFFF". For example, the Solicited-Node multicast address corresponding to the IPv6 address A node is required to compute and join (on the appropriate interface) the associated Solicited-Node multicast addresses for all unicast and anycast addresses that have been configured for the node's interfaces (manually or automatically). Example, I think 😉 My bloc client :
|
Beta Was this translation helpful? Give feedback.
-
|
I am writing a new comment for information : I'm not sure why, but I'm not getting any packet from the UK site ; I think I disabled the "web balancers" for the DE and UK sites, though. Otherwise, the connections are holding up well, I'd say ! See you later, In fact, I hadn't configured the outdated IPv6 GUA address of my main card on the UK site; therefore, it's malfunctioning. This is really strange on OVH Cloud VPSs. I was wondering why my "Apache Web balancer" server, which polls the backend web servers every 5 seconds, wasn't sending any packet. CF : And yet I don't understand WHY the source address is the bridge " Listening with TCPDump I see the correct IP address ; that of the "UK" site " And as a result, I have traffic from the "UK" site in Great Britain. Romain. |
Beta Was this translation helpful? Give feedback.
-
|
Good evening, good morning. Here are two links to my router and my server configurations at home :
The IPv6 ULA (Unique Local Address) network configuration from my home to the servers ; shown in the image : If that helps. TODO : Installing an Active Directory (currently it's just the Samba service) - Introduction : AD integration on Ubuntu Server. I need to (re) install an Active Directory (PDC and BDC) to work/verify that local network neighbor queries are working and transiting through inter-sites networks ; that they go to the right place based on the IPv6 prefix length and distribute to the correct networks. 😉 |
Beta Was this translation helpful? Give feedback.
-
|
Nothing to See Off Topic : Hello, I tried to delegate IPv6 addresses to configure the reverse of my IPv6 GUA (Global Unicast Addresses) addresses (FRANCE Orange ISP with Livebox 5). I started with the IPv6 ULA (Unique Local Addresses), the " Delegation of IPv6 ULA addresses for name resolution over IPv6. Fiber - IP❤6 - Routers - Configuration Networks - Delegation rDNS (French Page) |
Beta Was this translation helpful? Give feedback.
-
|
Hello, To demonstrate : I love it ! It's super smooth, via network neighbors, through VPN, and on the local site, all with ULA IPv6 addresses (xLAN). I transfer files from my smartphone to network shares very easily; it's fantastic. Thanks to the strongSwan development team. I connected the Samba (Network Neighborhood) of one of the Linux Containers (LXC) of one of the Virtual Machines in Canada - from my smartphone connected in France via the strongSwan v6 VPN. If you'd like to see the logs - it doesn't necessarily mean anything to me personally; I see an incorrect frame; I have no idea why ; if that helps 😉 IPv6 ULA SAMBA (dc1) : " For your information, I have my home computer connected to Samba (dc1) : " TCPDump logs ; if that means more to you than it does to me : vpn / strongSwan_home-a53S_to_dc1-audio_play_with_soft_files_gestionnaire_android-TCPDump.log (11Mo) Command from DC1 server (Samba) : After 1 hour : The directory I'm reading : Index of / bazikdjshop 🎜 by the Android 12 file manager 🤩 (via "microsoft-ds" protocol and not "https"). If you want to download my whole Life, or just the BasikDJShop directory (the mp three 🎜 extracts) ; you can use my anonymous FTPs whether you are French, American, German, Spanish, Italian or Canadian or elsewhere : "ftp.lab3w.com" - The SSL/TLS certificate is expired but it's not too serious 🫣 🤫 🤪 Romain. |
Beta Was this translation helpful? Give feedback.
-
DHCPThe dhcp plugin for libcharon allows to forward requests for virtual IP addresses to a DHCPv4 server. When an IKEv2 client requests a virtual IP address via a CP configuration payload, the plugin allows the daemon to forward this request to a DHCP server. By default the plugin uses broadcasts, but a designated DHCP server can be configured in strongswan.conf. The MAC address used in the DHCP request is either randomly generated or can optionally be based on the IKEv2 identity of the client. DNS/WINS server information is additionally served to clients if the DHCP server provides such information. In combination with the farp plugin this plugin lets a road-warrior fully act as a client on the local LAN of the responder. strongSwan 6.0.1 : New Feature Additions The new interface_receive option for the dhcp plugin allows binding the receive socket to a different interface than the send socket. For example, setting this to lo can be useful if the DHCP server runs on the same host and binding both sockets to e.g. the internal bridge interface won't work because the responses are sent via loopback interface (a50ed30, 00d8c36). Fixes A regression in the dhcp plugin, due to a refactoring in 5.9.14, has been fixed. It affected setups where the DHCP server is running on the same host its responses are sent via loopback interface (abbf9d2). For memo and information on possibilities with DHCP server client requests : I'm adding these " For fun and French solidarity, how does x0r do it : Configure an AudioCodes FXO gateway with Asterisk 😉 Complete examples of the " # pci06 / ba0bab -> https://github.com/pci06/ba0bab CF : https://github.com/pci06/ba0bab/blob/master/original/etc/dhcp/orange/832-6.conf 😇 Here, I am connected to the "responder" in IPv4 and I send a request to be delegated a block of IPv6 addresses - I don't know if it can be adapted through strongSwan - but it can. So, the " Simple Exemple I created this file : I got this " Here, below, on the server side, I think; based on the link-local address " This is an internet box, we can't change the "Link-Local Address"; also, without modifying the MAC-ADDR on a Linux router or other router, we won't change the LLA either, I would say ;) Then first test : We therefore see that : IAPREFIX -> " My comment on LaFibre.info : How to make multiple IPv6::/64 networks in the Orange IPv6::/56 block (French Page) 😉 Let's not forget the ICMPv6 announcements of the NDP (Network Discovery Protocol), all of this is related to and supported by strongSwan v6. Example of RaDvD daemon configuration for NDP (Network Discovery Protocol) :
Configure " This allows you to have the gateway in LLA (Link-Local Address) on the "child" machines and to use the "neighbor proxy". I adding : Example on a DHCPdv6 configuration (server). DIAMOND EDITIONS : 6.4. What about IPv6 address reservation based on MAC address ? (French Page) Address reservation on DHCPv6 works externally in a somewhat similar way to what we know under IPv4, but it is not based on the client's MAC address but on its DUID (DHCP Unique Identifier). Each server and each client have a DUID. There are three types of DUIDs, which are described in [RFC3315]:
The identifiers are generated when the server or client is first activated and when a physical interface is replaced. Outside of these cases, they are not intended to be modified. The easiest way to obtain them is to retrieve them from the log file (the leases files), either on the client for the client, or on the server... for the server. Let's see how we could set this up for an "initiator client". We adapt the DHCPv6 server configuration to reserve a MAC address for the client : Before restarting the server and client, clean the " Restart the server : then the client : The machine will obtain its reserved address and its " And DHCPd v4 configuration server : Come on, let's dance, thank you "Farley Jackmaster Funk Boiler Room Detroit DJ Set" 🎜 On my website ZW3B.TV (no ad breaks). |
Beta Was this translation helpful? Give feedback.
-
|
Hello, For those who would like to try it out : Download the Windows Server 2022 ISO here : https://www.microsoft.com/en-us/evalcenter/download-windows-server-2022 Evaluation copies are valid for 180 days (6 months), but you can reactivate them 5 or 6 times for 180 days each time. 🤠 |
Beta Was this translation helpful? Give feedback.
-
|
Hi, So, to continue my secure local network. I installed "Microsoft Windows Server 2022 Standard Evaluation" on my Promox VE by following this tutorial - I'll see if I can manage sending Active Directory packets to other machines connected to the networks.
Honestly, I don't know "much" about managing a domain controller and Network Policy Server's Network Policy and Access Services ; I'll give it a try ; I'm also not familiar with "Microsoft-IIS, the web server." For those who don't know, it's very comprehensive but requires a fee ; Windows Server (~€1,500). The "server" machines :
😁 Good evening. Romain. For those who would like to see other types of links, I have a great web page with this week's news that you can find on my #ZW3B websites. @+ |
Beta Was this translation helpful? Give feedback.
-
|
Application : https://www.youtube.com/watch?v=BB8UlhfEQyY I like this little VPS 👍 I'm bringing this topic back up. (◕‿◕) |
Beta Was this translation helpful? Give feedback.
-
IDN (Internalized Domain Name) -----My new domain « WorldSite » eXteNsion : IP ❤10.ws of the Pacific Ocean The .WS extension is the official extension of the Samoa « Islands », also used for « WebSite ». IP❤10.ws - 4to6 | 6to4 (Internet Protocol vs 10) 🤠 Keywords : network ip, IP❤10, ipv10, ip10, ipv4, ip4, ipv6, ip6, lab3w, lab3w.orj, o.romain.jaillet-ramey, firewall ipv6, icmpv6, zw3b ZW3B's LAB3W O.Romain.Jaillet-ramey (Romain). |
Beta Was this translation helpful? Give feedback.
-
Hello, I just purchased two internalized domain names and I have a few requests for my system configuration. For example: I just started this discussion in French on Debian-Fr.org 🇫🇷 How can I configure my Linux system to comply with the IDNA standard?
Unicode / Converter PunyCode / ASCII / BASH
I'm looking to have my domain names "written in internalized language/emoji" available with my usual Linux commands. The parameter string is not correctly encoded The parameter string is not correctly encoded 😉 Olivier Romain Jaillet-ramey - Founder ZW3B.FR and more. The IPv4 Web Balancer : https://www.⛔🔜.ws/balancer-manager - Converter PunyCode
...
Does anyone know how to configure the PuTTY (Windows) environment to change the background and letter colors? To make my "red" emoji a "green" emoji in my Linux console. Because I'm an admin in my SSH console 😇 Please. If you can make me blink ⛔- I will love you until I die ; even if it wasn't on my heart ❤ to make it beat. I will love you all my life. A bit like reading logs in color : 🇫🇷 Read logs with command tail -f file with strings color? according to the expression but in the BASH console. I succeeded in this, but that forces me to put in the IPs in the
The IDN encoding (emojis in email addresses, domain names, etc.) is in PunyCode. Otherwise, I looked at the special characters ; For example : XML Entity Definitions for Characters (3rd Edition) And on WikipediA :
@+ Sorry, I made a mistake in my DNS address.
I add this domain extension; And there is a BIG PROBLEM (WikipediA: .st); it tries to make a "DNS" delegation [spoiler]SEC[/spoiler] on my domain, but it can't do it ; domain that I have not yet signed.
My DNS configuration OK in Local : IP -> Other bug Google Public DNS is returning to me → Result for xn--hwgz2tba.st/A with DNSSEC validation and without DNSSEC detail... Romain |
Beta Was this translation helpful? Give feedback.
-
|
How can I make it so that in TCPDump @the-tcpdump-group I can see the IDN (Internalized Domain Name)? I see " Like the Thanks. 😉 I make my other PunyCode URLs on my other DNS child zones ;) OVH allows me to configure only one DNS and one rDNS for each VPS. I'm going to configure my system in the IDNA version: 😃 Does strongSwan decode PunyCode to result in command output as ASCII/Unicode text ? I'll have to try it. 🥲 I made my DNS zone – OK :
It works -- or not - Apart from the flags not showing up -- Network Neighborhood connection not working - Only visible in Network. (WIN 11 Home) - WINDOWS Server 2022 (Not Working).
I still have to make my rDNS IPv6 SLA zones "
The tracert (Windows) returns PunyCodes to me – I say this because I haven't done my reverse DNS yet. Country flags, please. Unicode / Converter PunyCode / ASCII / BASH in French on Debian-Fr.org 🇫🇷 How can I configure my Linux system to comply with the IDNA standard? |
Beta Was this translation helpful? Give feedback.
-
|
I wanted to say : x509 is a Lord !
Thanks @tobiasbrunner too. |
Beta Was this translation helpful? Give feedback.
-
|
@mathiasbynens Could you please make it so that when I type « vps.🇬🇧.ip❤10.ws » it shows up in my browser's address bar ?
That's not very communicative. #PunyCode Thanks a lot, |
Beta Was this translation helpful? Give feedback.
-
|
In "MS Windows 11 Home," the DNS names of my internationalized / IPv6 ULA/SLA machines work on "connect to a network drive," yay 😉 It's much prettier than the literal Windows IPv6 "network mount." For example, I'm connected to my Canadian "Domain Controller" from my home in France using an IPv6 ULA address that transits to strongSwan. Below I have added multiple names for the same IPv6 ULA address.
😉 My last Facebook post - IDNA 😉 Add comment : « iperf3-20251013.txt »
Romain Thanks to Léon from LaFibre.info for telling me that it's not related to the subject 😉 but if you want to discuss it (despite everything) with those around you ; that way there will be several of us 😎 hello. First juice 🍋🟩 - Reverse DNS zone "
|
Beta Was this translation helpful? Give feedback.
-
|
Weird : KO OK route table strongswan route table : Address :
VPS.AU 👍 VPS.UK 👍 First juice 🍋🟩 - Reverse DNS zone " These "machines" / And switch the
Thanks. That's stupid ; Lemony 🍋"without space"🟩 Otherwise, I would have put a "thing" after " I'm looking for...
# 2025/10/15 # rDNS ULA/SLA Reverse DNS zone "c.e.f.ip6.arpa" + Delegation of child zones (by sites). Finally, this one is funny. By the way, how did you create a "solar system" emoji ? Do you have to put the planets in the right order ? But which way around ? Who created whom ; with whom ; with two or more! ?
I made a little reverse IPv6 GUA configuration on my DNS : And ULA : It's pretty neat, I think. Result : Good luck, happy sites setup. @+ An international |
Beta Was this translation helpful? Give feedback.
-
|
Something like this ; my network.
If you see me, give me a Like ! |
Beta Was this translation helpful? Give feedback.
-
|
Published on October 17, 2025 at 6:20 p.m GMT+2. Science Look up to the sky to admire comets « Lemmon » and « Swan » in October 2025 2 comets for the price of one ☄️☄️ Article on Numerama by Diane Hassoun. ---It's extraordinary 😁 |
Beta Was this translation helpful? Give feedback.
-
|
SLA/ULA - OK rDNS IPv6 and routes SLA/ULA IPv6 GUA TODO @strongX509 : #2909 |
Beta Was this translation helpful? Give feedback.
-
|
To be able to scan/play on IPv6::/104 blocks you need to find something that looks like this (could it be the block...). As for :
My ULA network "on site
My admin ULA network "on site
I don't really know. All networks SWAN - example for on site
For a machine (one network) :
For a machine + VM (Central unit, smartphones) :
🙂 |
Beta Was this translation helpful? Give feedback.
-
|
For fun : I have just installed Debian 13; I wanted to configure an IPv6 ULA/SLA/GUA network for my new machine with LinuX Containers and services, etc... (to be continued).
So, and; on the other hand, the output of the «
See : PuTTY - Release 0.83 How can I change the color of IPv6 addresses like the IPv4 addresses ? Because right now it's awfu ; you can't see anything. Users already have trouble with IPv6, but this is really frightening - it's not appealing at all. Otherwise, I admit it's a good idea ; Nice display of the « Otherwise, Server information for « « See you later. Me, I'm starting an installation. For my part, I created a discussion on Debian-Fr.org (I did some title/URL rewrites). 🇫🇷 🇨🇦 Vous êtes sympat dans Debian ; mais là c’est de trop! @gospo 😇 😉 Happy configuring ! Romain. |
Beta Was this translation helpful? Give feedback.
-
|
Note from myself 2025-11-03: I created a homepage for my server in Canada at OVHCloud : SRV.🇨🇦.◕‿◕.ST 89::1/64
Microsoft Ignite - Configure Network PoliciesNetworking documentation > Network Policy Server (NPS) > Manage NPS > Configure Network Policies Applies to: ✅ Windows Server 2025, 2022, 2019, 2016, ✅ Azure Local 2311.2 and later My 🪟 Windows Server 2022 Configuration WinSrv IPv4 : « Note from myself 2025-11-05 : I created a homepage for my server in France at Hostinger : HST.🇫🇷.◕‿◕.ST 95::1/128 Greets, |
Beta Was this translation helpful? Give feedback.
-
|
Hi, I already reported this for the OVHCloud ISP ; now it's for the Hostinger ISP (they must not be aware of it) ; on their KVM. To summarize ; I am forced to activate my IPv6 GUA in obsolete mode in order to be able to catch the SWAN networks (those in table 220); and therefore ; afterwards I can no longer access the GUA - The server is still accessible from the outside on the GUA. Code examples for understanding : So : " I can successfully connect to servers on the internet using IPv6: My SWAN configuration : The v6 routes : ULA v6 routes between Secure Sites : Then, for example, I want to capture the machine " ⏷ In the image above ↑
No response ; I check the route and I realize that it uses the GUA instead of the strongswan table. So; I change and make the IPv6 GUA address obsolete; and at that moment I can indeed connect to the SWAN but not the Internet; I also notice that the route uses the address of my bridge "incusbr0" as "address src" and via the "gateway for internet" to communicate with the IPv6 address of another site. And as a result, I have Forbidden entries on the Backends of ZW3B.TV ; from this frontend in France (since I have ; I authorize the IPv6 SLA address " I have 4 front-ends (specifically for testing good connectivity and comminucation protocols ; and hosting providers) ; depending on the browser, the website can be accessed. I have not (yet) contacted Hostinger's support service ; their chat assistant. I don't know what to do anymore ; except throw it all away ! What's going on in this world !? On container ULA : " To verify that the GUA of the Hostinger KVM (in obsolete mode) is accessible from the Internet. Note 2025/11/23 We found the solution ; using Hostinger's Kodee chatbot. I added this "rule" ; I changed the IPv6 GUA address back to " Important
Romain. |
Beta Was this translation helpful? Give feedback.
-
|
Hello, On Hostinger KVMs running Debian GNU/Linux 13 (trixie) as an example ; I have difficulty managing network inputs and outputs. I need to configure a "strong firewall" with "connection tracing", or more commonly known as a "stateful firewall". The description on this page:
Romain. Note of me 20251203 : I believe we need to configure rules for multiple routes ; Dual Routes no longer in recent FW? Otherwise ; off-topic :) Exemple : but ; The flags " IDN Applications ;) |
Beta Was this translation helpful? Give feedback.
-
|
I created a page using RRD (Robin Round Database) to track ping latency between the IPv4 addresses of my servers. It's located in the " For example, here's the view (web page) from my gateway in France: RRD - Graphs Latency :-: GATE.🇫🇷.◕‿◕.ST @st.◕‿◕.🇫🇷Connection on ASN 47583 Hostinger in Paris (FR), France (UTC+1).
@st.◕‿◕.🇨🇦Connection on ASN 16276 OVHCloud in Montreal (CA), Canada (UTC-5). I ping from my servers to the Canadian server : " The tutorial is here : https://calomel.org/rrdtool.html In addition to the MRTG graphs : MRTG :-: GATE.🇫🇷.◕‿◕.ST Regards, If you're on the line, set up this script to find out where packet loss is occurring. Please connect it between your network and someone else's to analyze the network. ;-) |
Beta Was this translation helpful? Give feedback.
-
|
Is there a problem with my routes ? Conn : Routes : but
And my strongSwan must have a route to the server ; a secure/encrypted link from :-/ Traceroute - OK ?! My DNS SWAN : |
Beta Was this translation helpful? Give feedback.



















Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
Hi,
To keep enginners, users, and administrators who use strongSwan informed.
Thanks for all your help, thanks to @tobiasbrunner 😍
How to configure #strongSwan v6 using the modern Versatile IKE Control Interface (VICI) and the #swanctl command-line tool in an #IPsec network, with #pki and #openssl tools for #NIST compliant Post-Quantum Cryptography #PQC.
Page translate : https://howto-zw3b-fr.translate.goog/linux/securite/strongswan-v6-0-x-for-swanctl-in-ipsec-by-ike-vici?_x_tr_sl=fr&_x_tr_tl=en&_x_tr_hl=auto&t=dark
#CyberSecurity #LAB3W #ZW3B #KEM
Page in French : https://howto.zw3b.fr/linux/securite/strongswan-v6-0-x-for-swanctl-in-ipsec-by-ike-vici
Romain - Founder ZW3B.FR | TV | EU | NET | COM | BLOG and more.
Read the INFOS.txt file in my StrongSwan 6.0.1 Configuration files n°7 ; there is some nice information - I like my "traceroute" tests from home (gate-fr / command-traceroute6.txt). It's tempting.
🤠
🌈 Quantum Key Distribution (QKD) - SPD_A photon counter from AUREA Technology.
By the way, we, in Europe want to catch the Moon and make it shine, illuminate it. #Moonlight #GPS #SafeSpaceLanding 🚩
Anchor IDN_Internalized_Domain_Name in this page.
Anchor rDNS ULA/SLA Reverse DNS zone "c.e.f.ip6.arpa" + Delegation of child zones (by sites).
Beta Was this translation helpful? Give feedback.
All reactions