The replay_window for child SA will always be 32 (hence enabled), there should be a setting in configure mode to set it to 0 instead of manually changing swanctl.conf on vyos 1.4 or ipsec.conf on 1.3, or using a start-up script
Description
Description
Details
Details
- Difficulty level
- Unknown (require assessment)
- Version
- -
- Why the issue appeared?
- Will be filled on close
- Is it a breaking change?
- Behavior change
- Issue type
- Improvement (missing useful functionality)
Event Timeline
Comment Actions
Probably under vpn ipsec site-to-site peer to have an option for replay_window enable or disable