Project

General

Profile

Actions

Bug #10418

closed

IPsec VTI address/mask selection not functional

Added by Danilo Zrenjanin about 4 years ago. Updated almost 4 years ago.

Status:
Resolved
Priority:
Normal
Category:
IPsec
Target version:
Start date:
04/03/2020
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.4.5
Affected Architecture:

Description

There are couple of oddities in 2.4.5.
1. Once the IPsec interface is assigned, it gets /32 subnet instead of /30.

ipsec1000: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> metric 0 mtu 1400
    tunnel inet 77.243.27.229 --> 178.148.171.201
    inet6 fe80::290:bff:fe7a:861b%ipsec1000 prefixlen 64 scopeid 0xb
    inet 10.6.106.1 --> 10.6.106.2 netmask 0xffffffff
    nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
    reqid: 1000
    groups: ipsec

2. After IPsec interface assignment it doesn't appear under Firewall/Rules

3. It still works and routes the traffic even though the interface has /32 subnet.

Actions

Also available in: Atom PDF