Although the tunnel has already been created, so why is this client trying to connect to an ip from outside the tunnel to an ip (100.64.100.1) in the rfc6598 shared address range? It also looks like there is no response to the client from that ip. Does that ip belong to a local service running on the pc or is the traffic actually leaking to the ISP?
