Project

General

Profile

Actions

Bug #1560

closed

IPsec GUI needs to reject duplicate subnets in phase 2s for a given phase 1.

Added by Jim Pingle almost 13 years ago. Updated almost 13 years ago.

Status:
Resolved
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
Start date:
05/26/2011
Due date:
% Done:

70%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.0
Affected Architecture:
All

Description

Currently, the GUI lets you specify the same source/destination subnet more than once in the list of phase 2 definitions. This includes listing the same subnet twice in a set of mobile phase 2s. This results in an invalid racoon configuration.

With a site-to-site phase 1, it doesn't appear to prevent racoon from starting but does log an error. With a mobile phase 1 it prevents racoon from starting.

Easy to reproduce by enabling mobile clients, setting up phase 1, and adding the same phase 2 in twice.

Actions

Also available in: Atom PDF