ClearFoundation Tracker - ClearOS
View Issue Details
0015961ClearOSapp-static-vpn-basic - Static VPN for Homepublic2017-08-02 13:022021-11-09 06:58
NickH 
 
normalfeaturehave not tried
closedwon't fix 
7.3.1 
 
0015961: Add VTI support to allow QoS to work in a tunnel
Libreswan from about v3.18 upwards allows the use of VTI interfaces so and route based tunnels. This allows interop with more devices, but, more importantly for ClearOS, it creates new interfaces for the tunnels and QoS can be applied to these interfaces. This then means you can guarantee bandwidth in a tunnel, say for VoIP.
It will require updating Libreswan from 3.15 to 3.18 or later (current is 3.20).
There is more information on the Libreswan Wiki at https://libreswan.org/wiki/Route-based_VPN_using_VTI, [^] comment 4 on this bug https://bugzilla.redhat.com/show_bug.cgi?id=1399883#c4 [^] and also on their mailing list.

At the moment the only way to achieve QoS in a net-net VPN is to use OpenVPN, but this is an entirely manual configuration.
No tags attached.
Issue History
2017-08-02 13:02NickHNew Issue
2017-08-12 19:41user2Statusnew => confirmed
2021-11-09 06:58NickHNote Added: 0016061
2021-11-09 06:58NickHStatusconfirmed => closed
2021-11-09 06:58NickHResolutionopen => won't fix

Notes
(0016061)
NickH   
2021-11-09 06:58   
VTI support is dead