На MikroTik поднят IKEv2-сервер с eap-авторизацией и кучей маршрутов в split-includes.
Windows 10 - подключается и импортирует все эти маршруты. А вот Linux (в том числе Android) со strongSwan - только первый из этой портянки.
charon-nm: 16[ENC] parsed IKE_AUTH response 5 [ CERT CERT IDr AUTH CPRP(ADDR MASK SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET DNS DNS) TSi TSr SA ]
charon-nm: 16[IKE] authentication of 'vpn.example.ru' with EAP successful
charon-nm: 16[IKE] IKE_SA vpn.example.ru (IKEv2)[2] established between 192.168.0.100[turbid]...1.2.3.4[vpn.example.ru]
charon-nm: 16[IKE] scheduling rekeying in 35981s
charon-nm: 16[IKE] maximum IKE_SA lifetime 36581s
charon-nm: 16[CFG] handling INTERNAL_IP4_NETMASK attribute failed
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5784] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: VPN connection: (IP Config Get) reply received.
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5790] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: VPN plugin: state changed: started (4)
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5791] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: VPN connection: (IP4 Config Get) reply received
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
kded5[1213]: plasma-nm: Unhandled VPN connection state change: 4
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5799] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: Data: VPN Gateway: 1.2.3.4
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5800] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: Data: Tunnel Device: (null)
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5800] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: Data: IPv4 configuration:charon-nm: 16[ENC] parsed IKE_AUTH response 5 [ CERT CERT IDr AUTH CPRP(ADDR MASK SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET SUBNET DNS DNS) TSi TSr SA ]
charon-nm: 16[IKE] authentication of 'vpn.seti-sk.ru' with EAP successful
charon-nm: 16[IKE] IKE_SA vpn.seti-sk.ru (IKEv2)[2] established between 192.168.0.100[demyanov-ia]...194.85.112.5[vpn.seti-sk.ru]
charon-nm: 16[IKE] scheduling rekeying in 35981s
charon-nm: 16[IKE] maximum IKE_SA lifetime 36581s
charon-nm: 16[CFG] handling INTERNAL_IP4_NETMASK attribute failed
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5784] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: VPN connection: (IP Config Get) reply received.
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5790] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: VPN plugin: state changed: started (4)
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5791] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: VPN connection: (IP4 Config Get) reply received
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
kded5[1213]: plasma-nm: Unhandled VPN connection state change: 4
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5799] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: Data: VPN Gateway: 194.85.112.5
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5800] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: Data: Tunnel Device: (null)
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5800] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: Data: IPv4 configuration:
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5800] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: Data: Internal Address: 10.126.39.244
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5800] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: Data: Internal Prefix: 32
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5800] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: Data: Internal Point-to-Point Address: 10.126.39.244
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5801] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: Data: Internal DNS: 192.168.77.235
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5801] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: Data: Internal DNS: 192.168.77.236
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5801] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: Data: DNS Domain: '(none)'
charon-nm: 16[IKE] installing new virtual IP 10.126.39.244
NetworkManager[649]: <info> [1628233106.5801] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: Data: No IPv6 configuration
avahi-daemon[644]: Registering new address record for 10.126.39.244 on enp3s0.IPv4.
NetworkManager[649]: <info> [1628233106.5814] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.seti-sk.ru (IKEv2)",0]: VPN connection: (IP Config Get) complete
charon-nm: 16[CFG] selected proposal: ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5800] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: Data: Internal Address: 10.126.39.244
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5800] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: Data: Internal Prefix: 32
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5800] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: Data: Internal Point-to-Point Address: 10.126.39.244
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5801] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: Data: Internal DNS: 192.168.77.235
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5801] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: Data: Internal DNS: 192.168.77.236
charon-nm: 16[CFG] handling INTERNAL_IP4_SUBNET attribute failed
NetworkManager[649]: <info> [1628233106.5801] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: Data: DNS Domain: '(none)'
charon-nm: 16[IKE] installing new virtual IP 10.126.39.244
NetworkManager[649]: <info> [1628233106.5801] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: Data: No IPv6 configuration
avahi-daemon[644]: Registering new address record for 10.126.39.244 on enp3s0.IPv4.
NetworkManager[649]: <info> [1628233106.5814] vpn-connection[0x563d6c68a4f0,65764ea9-4823-4be6-935f-599aa4b3b3a5,"vpn.example.ru (IKEv2)",0]: VPN connection: (IP Config Get) complete
charon-nm: 16[CFG] selected proposal: ESP:AES_CBC_256/HMAC_SHA2_256_128/NO_EXT_SEQ