Project

General

Profile

Actions

Bug #3812

closed
EL CB

IPSec validation should prevent phase2 policies(subnets) to include remote peer on it

Bug #3812: IPSec validation should prevent phase2 policies(subnets) to include remote peer on it

Added by Ermal Luçi about 12 years ago. Updated almost 12 years ago.

Status:
Resolved
Priority:
Normal
Category:
IPsec
Target version:
Start date:
08/18/2014
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:

Description

It would be nice to have validation of phase2 subnets to not include the remote peer of ipsec phase1 to avoid loops after tunnel establishment.

JT Updated by Jim Thompson about 12 years ago Actions #1

  • Tracker changed from Feature to Bug
  • Assignee set to Ermal Luçi
  • Target version set to 2.2

JT Updated by Jim Thompson about 12 years ago Actions #2

  • Affected Version changed from All to 2.2

CB Updated by Chris Buechler almost 12 years ago Actions #3

  • Status changed from New to Feedback
  • Assignee changed from Ermal Luçi to Chris Buechler
  • Affected Version changed from 2.2 to All

fix pushed and tested, leaving for further testing and confirmation. The check only prevents P2s where the local+remote of the P2 both fall within the interface and remote-gateway of its P1. Seems to work and cover all circumstances where that would be a problem.

CB Updated by Chris Buechler almost 12 years ago Actions #4

  • % Done changed from 0 to 100

Applied in changeset commit:6c3be3650008801aaa1579dca67b0588c04b8e18.

CB Updated by Chris Buechler almost 12 years ago Actions #5

  • Status changed from Feedback to Resolved

this is good

Actions

Also available in: Atom