Page MenuHomeVyOS Platform

Multiple IPSEC SA not initiating/IPSec SA not renewing
Closed, ResolvedPublicBUG

Description

When multiple IPsec Site to Site tunnels are configured only 1 SA will come up. That 1 SA tunnel will not renew without restarting the strongswan service manually.

Details

Version
2025.03.12-1116-rolling
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)
Forum thread
https://forum.vyos.io/t/multiple-ipsec-tunnels-not-coming-up/16249

Event Timeline

Add a set of commands to reproduce (from both sites)

Viacheslav changed the task status from Open to Needs reporter action.Tue, Mar 18, 5:51 PM
CPEng claimed this task.

I'm sorry, all it took was to disable PFS. PFS prevented future SA's from happening due to a policy mismatch.