Project

General

Profile

Actions

Regression #11910

closed

IPsec status tunnel descriptions are incorrect

Added by Jim Pingle almost 3 years ago. Updated over 2 years ago.

Status:
Resolved
Priority:
High
Assignee:
Category:
IPsec
Target version:
Start date:
05/12/2021
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
22.01
Release Notes:
Default
Affected Version:
2.5.2
Affected Architecture:

Description

Moving from internal Redmine since this affects CE and Plus and isn't hardware-dependent.

Original description:

I'm currently seeing wrong tunnel descriptions for site to site ipsec tunnels under 'status > ipsec'.

21.05-DEVELOPMENT (amd64)
built on Thu Apr 29 12:02:40 EDT 2021
FreeBSD 12.2-STABLE

Attached are images which indicate what I'm talking about.

I've seen this for at least a few weeks since I've been testing dev builds.

It survives reboots, and upgrades, and I see the wrong tunnel name with 'ipsec statusall' as well.

See NG 6284 for the attachments.

My note:

Probably something with the shift in numbering that Renato recently worked on (#11794). In the status output that cjl tunnel is "con8" which normally would be associated with the P1 that has an ikeid of 8, but the tunnel with an ikeid of 8 is Bob. So somehow it's not forming the expected connection numbers or it's not properly checking against the right reverse mapping when doing the status.


Files

Screen Shot 2021-06-04 at 9.32.55 AM.png (17.4 KB) Screen Shot 2021-06-04 at 9.32.55 AM.png Chris Linstruth, 06/04/2021 08:35 AM
Screen Shot 2021-06-04 at 9.32.42 AM.png (40 KB) Screen Shot 2021-06-04 at 9.32.42 AM.png Chris Linstruth, 06/04/2021 08:35 AM
ipsec_status.png (56.6 KB) ipsec_status.png Marcos M, 06/11/2021 05:06 AM
widget_overview.png (4.7 KB) widget_overview.png Marcos M, 06/11/2021 05:06 AM
widget_tunnels.png (7.65 KB) widget_tunnels.png Marcos M, 06/11/2021 05:06 AM
vti.png (51.4 KB) vti.png Marcos M, 06/25/2021 12:55 PM
ipsec_wrong_description.png (98.4 KB) ipsec_wrong_description.png Charles Hamilton, 08/02/2021 07:19 AM

Related issues

Related to Regression #11794: IPsec VTI interface names are not properly formed for more than 32 interfacesClosedRenato Botelho04/09/2021

Actions
Has duplicate Bug #12123: 2.5.2 Ipsec Tunnel Status Dashboard Widget - Count of active tunnels, and Inactive tunnels is wrongDuplicate07/10/2021

Actions
Actions

Also available in: Atom PDF