pivpn import: adds ::/0 to a full tunnel without IPv6

pivpn without IPv6 writes ALLOWED_IPS="0.0.0.0/0", so imported clients sent IPv6 around the tunnel. The import now adds ::/0 when IPv4 is a full tunnel, so the server drops IPv6 instead.
This commit is contained in:
Daniel Redetzke
2026-10-07 04:42:16 +03:00
parent 58975074ab
commit f69f707af3
2 changed files with 9 additions and 4 deletions
+5
View File
@@ -95,6 +95,11 @@ func readPivpn(root string) (*pivpnSetup, error) {
srv.ClientDefaults.AllowedIPs = append(srv.ClientDefaults.AllowedIPs, p.Masked().String())
}
}
// pivpn without IPv6 writes only 0.0.0.0/0, so clients would send IPv6
// around the tunnel. ::/0 makes the server drop it instead.
if fullTunnel(srv.ClientDefaults.AllowedIPs, false) && !fullTunnel(srv.ClientDefaults.AllowedIPs, true) {
srv.ClientDefaults.AllowedIPs = append(srv.ClientDefaults.AllowedIPs, "::/0")
}
srv.ClientDefaults.Keepalive, _ = strconv.Atoi(vars["pivpnPERSISTENTKEEPALIVE"])
// Clients