Project

General

Profile

Bug #9049

IPSec statuspage shows both connected and connecting tunnel

Added by Ges Ture 5 months ago. Updated 5 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
-
Start date:
10/18/2018
Due date:
% Done:

0%

Estimated time:
Affected Version:
2.4
Affected Architecture:

Description

Since bugnumber 8117 has been served off as not a bug, and no further response is given I'd like to re-open this bug. It's version 2.4.4 now and the bug described in #8117 still exists. It's most annoying that there are two connections in the status page, one 'connecting' and one 'connected'. It's very hard to see which is correct. I do confirm that it has to do with tunnels that where initially set up as initiator, but due to connection issues where changed to responder only. Now once in a while the changed 'initiator' connection appears as 'connecting' in the status page, while the 'responder' is already connected. It also seems to be GUI related, as the CLI does not show these duplicate entries.

IPSec double connections.png (28.1 KB) IPSec double connections.png Duplicate tunnel connections in IPSec Status Page Ges Ture, 10/18/2018 07:39 AM

History

#1 Updated by Ges Ture 5 months ago

Ges Ture wrote:

Since bugnumber 8117 has been served off as not a bug, and no further response is given I'd like to re-open this bug. It's version 2.4.4 now and the bug described in #8117 still exists. It's most annoying that there are two connections in the status page, one 'connecting' and one 'connected'. It's very hard to see which is correct. I do confirm that it has to do with tunnels that where initially set up as initiator, but due to connection issues where changed to responder only. Now once in a while the changed 'initiator' connection appears as 'connecting' in the status page, while the 'responder' is already connected. It also seems to be GUI related, as the CLI does not show these duplicate entries.

It seems to be related to the pfsense_ipsec_list_sa() function, as in line 87 of the status_ipsec.php a list of ipsec connections is queried. Every once in a while the old 'initiator' connections appear in this list and are shown in the view.

Also available in: Atom PDF