Project

General

Profile

Actions

Bug #16158

closed

IPsec allows deleting P1/P2 entries with an assigned VTI

Added by dylan mendez 6 months ago. Updated 6 months ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
24.11
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

Input validation does not prevent user from deleting a P1/P2 with a VTI assigned.

Also the IPSec interface on the GUI assigns itself to a random interface, at least visually because the interface doesn't break or seem to notice.


Files

clipboard-202504221835-hmb4v.png (22.6 KB) clipboard-202504221835-hmb4v.png dylan mendez, 04/23/2025 12:35 AM
clipboard-202504261027-vpcla.png (102 KB) clipboard-202504261027-vpcla.png Danilo Zrenjanin, 04/26/2025 08:27 AM
clipboard-202504261028-rrrqj.png (93.2 KB) clipboard-202504261028-rrrqj.png Danilo Zrenjanin, 04/26/2025 08:28 AM
Actions #1

Updated by dylan mendez 6 months ago

  • Subject changed from 24.11 IPSec Input Validation Issue - IPSec allows deleting a P1/P2 with a VTI Interface Assigned to IPSec allows deleting a P1/P2 with a VTI Interface Assigned
Actions #2

Updated by Danilo Zrenjanin 6 months ago

I couldn't reproduce it on:

25.03-BETA (amd64)
built on Thu Apr 24 19:28:00 UTC 2025
FreeBSD 15.0-CURRENT

I am receiving a warning message regardless of whether I attempt to remove Phase 1 or Phase 2.


Actions #3

Updated by Danilo Zrenjanin 6 months ago

  • Status changed from New to Feedback
Actions #4

Updated by Danilo Zrenjanin 6 months ago

I am getting the same results on 24.11 pfSense Plus. Everything works as expected.

Actions #5

Updated by Christopher Cope 6 months ago

  • Status changed from Feedback to Incomplete

Tested on

25.03-BETA (amd64)
built on Thu Apr 24 15:28:00 EDT 2025
FreeBSD 15.0-CURRENT

Everything is working as expected. If there are extra steps needed to reproduce this please detail them here. As it is, I'm marking this Incomplete.

Actions #7

Updated by dylan mendez 6 months ago

  • Status changed from Incomplete to Closed
Actions #8

Updated by Jim Pingle 6 months ago

  • Subject changed from IPSec allows deleting a P1/P2 with a VTI Interface Assigned to IPsec allows deleting P1/P2 entries with an assigned VTI
Actions #9

Updated by Jim Pingle 6 months ago

  • Category changed from Interfaces to IPsec
Actions

Also available in: Atom PDF