Page MenuHomeVyOS Platform

ipsec site-to-site: Support binding multiple tunnels to one VTI, customizing local and remote traffic selectors
Open, LowPublicFEATURE REQUEST

Description

Now that we use XFRM under the hood, there is no technical constraint that a single tunnel must map to a single VTI (XFRM) interface. It is perfectly possible to bind multiple tunnels to one interface, either for redundancy or to reduce administrative overhead with several tunnels each configured with non-overlapping traffic selectors.

Scope of work:

  1. Allow the local and remote traffic selectors to be configured when VTI is in use. This may have value on its own, e.g. if users want to change the default of all IPv4 and IPv6 traffic.
  2. Modify ipsec hooks that translate tunnel up/down into interface up/down to logically handle multiple tunnels bound to one interface.

Details

Version
-
Is it a breaking change?
Perfectly compatible

Event Timeline

lucasec created this object in space S1 VyOS Public.
dmbaturin edited projects, added VyOS Rolling; removed Restricted Project.Oct 14 2024, 10:53 AM
dmbaturin changed Is it a breaking change? from Unspecified (possibly destroys the router) to Perfectly compatible.
dmbaturin changed Issue type from Unspecified (please specify) to improvement.
syncer moved this task from Need Triage to Backlog - Feature Requests on the VyOS Rolling board.
syncer changed the subtype of this task from "Task" to "Feature Request".