When multiple IPsec Site to Site tunnels are configured only 1 SA will come up. That 1 SA tunnel will not renew without restarting the strongswan service manually.
Description
Description
Details
Details
- Version
- 2025.03.12-1116-rolling
- Is it a breaking change?
- Unspecified (possibly destroys the router)
- Issue type
- Bug (incorrect behavior)
- Forum thread
- https://forum.vyos.io/t/multiple-ipsec-tunnels-not-coming-up/16249
Event Timeline
Comment Actions
I'm sorry, all it took was to disable PFS. PFS prevented future SA's from happening due to a policy mismatch.