Project

General

Profile

Actions

Bug #16868

open

Static route with Alias as destination network doesn't install itself in the routing table under some conditions

Added by Georgiy Tyutyunnik about 2 hours ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Aliases / Tables
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Default
Affected Version:
Affected Architecture:

Description

Steps to reproduce the issue:
1) HA cluster with a routed IPSec to a remote host. IPSec tunnel source IP is the CARP;
2) Firewall alias type Network with some network in it;
3) routed IPSec assigned as the interface, resulting gateway is set as unmonitored;
4) static route with the destination set as that Firewall alias with type Network, with gateway set as routed IPSec unmonitored gateway;
5) the route is installed into the main node route table correctly;
6) trigger the failover via CARP maintenance mode. Now both nodes do not have this route in the routing table.
7) trigger the failback. Now both nodes still do not have this route in the routing table.

If you re-save that Firewall alias with type Network, the route gets installed into the routing table again.
This issue cannot be reproduced if the static route in question has a network (and not alias) as the destination network.

status outputs after the failover-failback from the test firewalls attached
CARP: 192.168.254.33
Routed IPSec gateway: 10.15.0.1
Firewall alias with type: Network test_alias_dst_route
Static route: to 192.168.33.0/24


Files

status_output_main.tgz (232 KB) status_output_main.tgz Georgiy Tyutyunnik, 06/05/2026 11:51 AM
status_output_backup (2).tgz (219 KB) status_output_backup (2).tgz Georgiy Tyutyunnik, 06/05/2026 11:52 AM

No data to display

Actions

Also available in: Atom PDF