Project

General

Profile

Bug #11226

IPSec VTI P2 traffic selectors default to address when defined as a network.

Added by Steve Wheeler about 2 months ago. Updated about 2 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Web Interface
Target version:
Start date:
01/06/2021
Due date:
% Done:

0%

Estimated time:
Affected Version:
All
Affected Architecture:
All

Description

The IPSec P2 edit page in the GUI (/vpn_ipsec_phase2.php) defaults the local and remote network type value to 'Address' when opening a VTI tunnel.

It does so even if the existing configured Network there is larger than a single address.

If making an unrelated change on that page, or saving without making any changes, the subnet value is removed from the configured P2 which is unexpected.

It shouldn't actually bring down a tunnel because the P2 will usually match 0.0.0.0/0 and the created interface is created as a /30. However is some uncommon is configured and required there it will do. In that situation you have to remember to set the type to Network whenever saving that page.

Changing the existing TS from a network to an address without the user selectign anything should not happen.

History

#1 Updated by Jim Pingle about 2 months ago

  • Target version set to CE-Next

Also available in: Atom PDF