AdguardTeam / AdguardTeam/AdGuardVPNForiOS

Check that private subnets are excluded in the "Integrated" mode

オープン
#152 コメント 0 件 リアクション 1 件 担当者 0 名 GitHub で見る
Enhancement High Priority: P4 TechAudit
主要言語
言語のデータがありません
スター
72
フォーク
11
PR マージ指標
30日以内にマージされた PR はありません

説明

This task requires cooperating with the server-side.

There are two options of excluding the local network in the IPSec case.

* First, we could set `excludeLocalNetworks` to `true` when configuring the connection. In this case, the tunnel should ignore the routes that it receives from the server-side.
* Second, they could be configured on the server-side.

In theory, we're currently using the second option. However, we received a couple of complaints that private subnets aren't excluded when using the Integrated mode.

Here's what we should do:

1. Check if it's excluded or not (try opening some intranet website when AdGuard VPN is enabled).
2. If it's not, try setting `excludeLocalNetworks` and see if we can control routes on the client side.
3. If we can control it on the client-side, we should do it this way as it allows us have client-specific routes.

Again, ideally, I'd prefer to have a low-level setting that controls excluded routes (like I explained here: https://github.com/AdguardTeam/AdGuardVPNForiOS/issues/151).

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。