! Fail closed - prevent leakage when VPN is down
In order to provide the option to disallow internet traffic when the EIP is disconnected, we need to find some non-root method of doing so or decide to use root methods and tell the user this setting requires root.
Possible non-root ways of doing so:
- persist-tun true, keeping the network device open and the routes in place, traffic will go through the "tunnel to nowhere" until the connection comes back up
(from redmine: created on 2013-03-19, closed on 2014-08-18)
- Relations:
- relates #5020 (closed)