Project

General

Profile

Bug #11891

strongSwan configuration contains incorrect structure for mobile pool DNS records

Added by Oleksandr Yermolenko about 2 months ago. Updated about 1 month ago.

Status:
New
Priority:
Normal
Assignee:
Category:
IPsec
Target version:
Start date:
05/05/2021
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
21.09
Release Notes:
Default
Affected Version:
2.5.1
Affected Architecture:
amd64

Description

Hello,

according to https://wiki.strongswan.org/projects/strongswan/wiki/Fromipsecconf:
old style configuration

rightdns=<ip>[,…]     

should be transformed to the next records:
connections.<conn>.pools=<poolname>
pools.<poolname>.dns=<ip>[,…]

but 2.5.1 version config generated in the following way:

pools {
}
mobile-pool {
        dns = 10.71.1.11,10.70.3.11
        28679 = "20" 
}

and connection

con-mobile-defaults {
...
        pools = radius-pool, radius
...

Associated revisions

Revision f528b6a9 (diff)
Added by Jim Pingle about 2 months ago

Ensure mobile IPsec pools are always in config. Issue #11891

Revision 4dd71873 (diff)
Added by Jim Pingle about 1 month ago

Back out recent changes in mobile IPsec

These changes led to the pool failing to load and thus clients could not
connect. Will revisit for future releases. Affects:

History

#1 Updated by Jim Pingle about 2 months ago

  • Status changed from New to In Progress
  • Assignee set to Jim Pingle
  • Target version set to 2.6.0

"radius" is a special internal pool in strongSwan, which expects settings to be returned from RADIUS and not defined in the configuration.

Though "radius-pool" should be defined to include the settings from "mobile-pool" as a template which would bring in the DNS settings from there, and that seems to not be making it into the config in certain cases.

#2 Updated by Jim Pingle about 2 months ago

  • Status changed from In Progress to Feedback

#3 Updated by Jim Pingle about 1 month ago

  • Plus Target Version set to 21.05

#4 Updated by Jim Pingle about 1 month ago

Already in 21.05 branch.

#5 Updated by Jim Pingle about 1 month ago

  • Subject changed from swanctl.conf/mobile-pool: incorrect config structure for DNS records to strongSwan configuration contains incorrect structure for mobile pool DNS records

Updating subject for release notes.

#6 Updated by Jim Pingle about 1 month ago

  • Plus Target Version changed from 21.05 to 21.09

Reverted RADIUS-specific parts of the change here for now, it was causing the configuration to fail. Can try again before the next release.

#7 Updated by Jim Pingle about 1 month ago

  • Status changed from Feedback to New

Also available in: Atom PDF