Page MenuHomeVyOS Platform

replay_window setting under vpn in config
Closed, ResolvedPublicFEATURE REQUEST


The replay_window for child SA will always be 32 (hence enabled), there should be a setting in configure mode to set it to 0 instead of manually changing swanctl.conf on vyos 1.4 or ipsec.conf on 1.3, or using a start-up script


Is it a breaking change?
Behavior change

Event Timeline

Viacheslav triaged this task as Normal priority.Jan 29 2024, 8:48 AM
Viacheslav added a project: VyOS 1.5 Circinus.
Viacheslav subscribed.

@stoicopa Do you have any ideas for CLI?

@stoicopa Do you have any ideas for CLI?

Probably under vpn ipsec site-to-site peer to have an option for replay_window enable or disable

c-po moved this task from Open to Finished on the VyOS 1.4 Sagitta board.