Project

General

Profile

Actions

Feature #14483

open

Conditionally reconfigure IPsec VTI interfaces only when necessary while applying IPsec changes

Added by Mike Moore 11 months ago. Updated 15 days ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
24.07
Release Notes:
Default

Description

I have at this time 4x IPsec VTI tunnels running eBGP.
When any change is made to any VPN tunnel (changes to the VTI address or a Phase 1 parameter change, etc) it forces all BGP peers to flap.
I assume this is the charon service restarting[havent validated that yet] but I have never seen this behavior on any other platform. Changes to a VPN configuration for a single peer shouldn't drop all routing for all peers.


Files

oci tunnel config.png (105 KB) oci tunnel config.png P1 and P2 configuration Mike Moore, 06/18/2023 12:24 AM
ipsec logs.png (297 KB) ipsec logs.png ipsec logs Mike Moore, 06/18/2023 12:26 AM
routing logs.png (391 KB) routing logs.png Mike Moore, 06/18/2023 12:35 AM
ping drops.png (56.7 KB) ping drops.png icmp drops through the tunnel Mike Moore, 06/18/2023 12:38 AM

Related issues

Has duplicate Bug #15285: Adding interfaces breaks FRR routing over IPsecDuplicate

Actions
Actions

Also available in: Atom PDF