Project

General

Profile

Actions

Regression #15430

open

Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on enc0

Added by Mike Moore 25 days ago. Updated 7 days ago.

Status:
New
Priority:
Normal
Category:
Routing
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
24.07
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

https://forum.netgate.com/topic/187632/24-03-frr-has-flapping-bgp-neighbors/3

In my set up there are two VPN types where dynamic routing is occurring. Wireguard and IPsec.
IPsec has been unstable since the upgrade to 24.03.
Digging into the issue it is related to the state policy change. Adding a specific rule for BGP from neighbor to my pfsense firewall on port 179 and changing the state policy to Floating allowed BGP to remain UP without the constant flapping.

Unsure why there is a difference between the two VPN types to pf.
Redmine for tracking.

No need to troubleshoot as problem is resolved. Noting here for additional follow up if required and corner case testing by developers if deemed necessary.


Related issues

Related to Feature #11395: Option to switch IPsec filtering modes to choose between ``enc`` and ``if_ipsec`` filteringClosedJim Pingle02/10/2021

Actions
Related to Bug #8686: IPsec VTI: Assigned interface firewall rules are never parsedNew07/24/2018

Actions
Has duplicate Bug #15431: Interface Bound Firewall State Policy Breaks IPsec VTIDuplicate

Actions
Actions

Also available in: Atom PDF