Bug #15087
open
IPsec Keep Alive does not update the gateway status
Added by Marcos M about 1 year ago.
Updated 12 months ago.
Description
If the IPsec gateway status is pending (e.g. on a VTI after bootup when the remote peer is an FQDN), the keep alive check will connect the P2, but the gateway status remains pending. Manually restarting dpinger updates the gateway status to online.
Files
I tried to replicate that behavior. I set FQDN for the Remote Gateway setup on both sides. Phase 2 in VTI mode. The gateway status never enters Pending mode, regardless of the actions I take (reboot, cold start, etc..).
Tried this and it doesn't even need to be a FQDN. The Gateway status page of any VTI with a /30 will almost always show "Pending" until you restart the dpinger service. Then it will show online.
If I select Type Network /30, the IPsec interface never gets the IP address. It gets only the gateway.
The only way to make it work is to select Address Type. In that case, the IPsec interface gets the IP address and the gateway.
After rebooting, the gateway status slowly goes back to the online status as expected.
I am testing on two ProxMox VMs running stock 23.09.1
Also available in: Atom
PDF