Project

General

Profile

Bug #11910

IPsec status tunnel descriptions are incorrect

Added by Jim Pingle about 1 month ago. Updated 3 days ago.

Status:
New
Priority:
Normal
Category:
IPsec
Target version:
Start date:
05/12/2021
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
21.09
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

Moving from internal Redmine since this affects CE and Plus and isn't hardware-dependent.

Original description:

I'm currently seeing wrong tunnel descriptions for site to site ipsec tunnels under 'status > ipsec'.

21.05-DEVELOPMENT (amd64)
built on Thu Apr 29 12:02:40 EDT 2021
FreeBSD 12.2-STABLE

Attached are images which indicate what I'm talking about.

I've seen this for at least a few weeks since I've been testing dev builds.

It survives reboots, and upgrades, and I see the wrong tunnel name with 'ipsec statusall' as well.

See NG 6284 for the attachments.

My note:

Probably something with the shift in numbering that Renato recently worked on (#11794). In the status output that cjl tunnel is "con8" which normally would be associated with the P1 that has an ikeid of 8, but the tunnel with an ikeid of 8 is Bob. So somehow it's not forming the expected connection numbers or it's not properly checking against the right reverse mapping when doing the status.

Screen Shot 2021-06-04 at 9.32.55 AM.png (17.4 KB) Screen Shot 2021-06-04 at 9.32.55 AM.png Chris Linstruth, 06/04/2021 08:35 AM
Screen Shot 2021-06-04 at 9.32.42 AM.png (40 KB) Screen Shot 2021-06-04 at 9.32.42 AM.png Chris Linstruth, 06/04/2021 08:35 AM
ipsec_status.png (56.6 KB) ipsec_status.png Marcos Mendoza, 06/11/2021 05:06 AM
widget_overview.png (4.7 KB) widget_overview.png Marcos Mendoza, 06/11/2021 05:06 AM
widget_tunnels.png (7.65 KB) widget_tunnels.png Marcos Mendoza, 06/11/2021 05:06 AM

Related issues

Related to Regression #11794: IPsec VTI interface names are not properly formed for more than 32 interfacesClosed2021-04-09

History

#1 Updated by Jim Pingle about 1 month ago

  • Related to Regression #11794: IPsec VTI interface names are not properly formed for more than 32 interfaces added

#2 Updated by Jim Pingle 27 days ago

  • Plus Target Version changed from 21.05 to 21.09

Renato said the fix for this will need to wait for the next release

#3 Updated by Chris Linstruth 12 days ago

Also seeing strangeness in the IPsec dashboard widget. Customer also reporting the active tunnel counts are incorrect in the widget but I can't duplicate that.

#4 Updated by Marcos Mendoza 5 days ago

I can replicate the active tunnel count being incorrect, as well as incorrect status, by using P1s with the option "Gateway duplicates". See attached.

Notice on the status image, con1 should have a description of "SiteA-B-IPsec WAN2" and have a different number in the IPsec VTI range.

#5 Updated by Steve Wheeler 3 days ago

I saw this behaviour when adding a VTI phase 2 to a system which already had a mobile IPSec tunnel defined.
Both configured to carry 0.0.0.0/0. Something over-matching there potentially.

Also available in: Atom PDF