Page MenuHomeVyOS Platform

L2TPv3: tunnel creation fails if the route to remote is added in the same commit
Closed, ResolvedPublicBUG

Description

When working with l2tp3v3 interfaces and bridge configuration, it's failing when submitting all changes in the same config.
Configuration used to reproduce the issue on a fresh install:

vyos@vyos# compare commands 

set interfaces ethernet eth0 address '10.10.10.1/24'
set interfaces loopback lo address '192.168.1.11/32'
set interfaces bridge br0 member interface eth3
set interfaces bridge br0 member interface l2tpeth333
set interfaces l2tpv3 l2tpeth333 encapsulation 'ip'
set interfaces l2tpv3 l2tpeth333 peer-session-id '33'
set interfaces l2tpv3 l2tpeth333 peer-tunnel-id '33'
set interfaces l2tpv3 l2tpeth333 remote '198.51.100.100'
set interfaces l2tpv3 l2tpeth333 session-id '33'
set interfaces l2tpv3 l2tpeth333 source-address '192.168.1.11'
set interfaces l2tpv3 l2tpeth333 tunnel-id '33'
set protocols static route 198.51.100.0/24 next-hop 10.10.10.2

[edit]
vyos@vyos# commit
[ interfaces l2tpv3 l2tpeth333 ]
Traceback (most recent call last):
  File "/usr/libexec/vyos/services/vyos-configd", line 157, in run_script
    script.apply(c)
  File "/usr/libexec/vyos//conf_mode/interfaces_l2tpv3.py", line 106, in apply
    l = L2TPv3If(**l2tpv3)
        ^^^^^^^^^^^^^^^^^^
  File "/usr/lib/python3/dist-packages/vyos/ifconfig/interface.py", line 350, in __init__
    self._create()
  File "/usr/lib/python3/dist-packages/vyos/ifconfig/l2tpv3.py", line 75, in _create
    self._cmd(cmd.format(**self.config))
  File "/usr/lib/python3/dist-packages/vyos/ifconfig/control.py", line 66, in _cmd
    return cmd(command, self.debug, env=env)
           ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/python3/dist-packages/vyos/utils/process.py", line 174, in cmd
    raise OSError(code, feedback)
FileNotFoundError: [Errno 2] failed to run command: ip l2tp add session name l2tpeth333 tunnel_id 33 session_id 33 peer_session_id 33
returned: 
exit code: 2

[[interfaces l2tpv3 l2tpeth333]] failed
Commit failed
[edit]
vyos@vyos#

We need two commits in order to make it work

[edit]
vyos@vyos# compare commands 

set interfaces ethernet eth0 address '10.10.10.1/24'
set interfaces loopback lo address '192.168.1.11/32'
set interfaces bridge br0 member interface eth3
set interfaces bridge br0 member interface l2tpeth333
set protocols static route 198.51.100.0/24 next-hop 10.10.10.2

[edit]
vyos@vyos# commit
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 encapsulation 'ip'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 peer-session-id '33'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 peer-tunnel-id '33'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 remote '198.51.100.100'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 session-id '33'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 source-address '192.168.1.11'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 tunnel-id '33'
[edit]
vyos@vyos# commit
[edit]
vyos@vyos#

Also, once stored, the configuration is not loaded properly after reboot:

[  OK  ] Finished Record Runlevel Change in UTMP.
[   16.761174] vyos-router[874]: Starting VyOS router.
[   19.249115] vyos-router[874]: Waiting for NICs to settle down: settled in 0sec..
[   22.255231] vyos-router[874]: Mounting VyOS Config...done.
[   37.508979] vyos-router[874]:  migrate system configure.
[   38.483480] vyos-config[880]: Configuration error

Welcome to VyOS - vyos ttyS0

vyos login: vyos
Password: 
Welcome to VyOS!

   ┌── ┐
   . VyOS 1.5.0
   └ ──┘  circinus

 * Documentation:  https://docs.vyos.io/en/latest
 * Project news:   https://blog.vyos.io
 * Bug reports:    https://vyos.dev

You can change this banner using "set system login banner post-login" command.

VyOS is a free software distribution that includes multiple components,
you can check individual component licenses under /usr/share/doc/*/copyright

vyos@vyos:~$ conf
WARNING: There was a config error on boot: saving the configuration now could overwrite data.
You may want to check and reload the boot config
[edit]
vyos@vyos# load
Loading configuration from 'config.boot'
Load complete. Use 'commit' to make changes effective.
[edit]
vyos@vyos# compare commands ç

set interfaces l2tpv3 l2tpeth333 encapsulation 'ip'
set interfaces l2tpv3 l2tpeth333 peer-session-id '33'
set interfaces l2tpv3 l2tpeth333 peer-tunnel-id '33'
set interfaces l2tpv3 l2tpeth333 remote '198.51.100.100'
set interfaces l2tpv3 l2tpeth333 session-id '33'
set interfaces l2tpv3 l2tpeth333 source-address '192.168.1.11'
set interfaces l2tpv3 l2tpeth333 tunnel-id '33'

[edit]
vyos@vyos#  commit
[edit]
vyos@vyos#

The same configuraiton works properly in Sagitta, with one commit, and no issues found during reboot

Details

Version
1.5.0, 1.4.4
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)

Event Timeline

c-po triaged this task as High priority.May 2 2026, 9:23 PM

I have built debug version of libvyatta-cfg and here is the priority during commit:

[PRIOTREE] path=interfaces bridge br0 prio=319 isValue=1 isTag=1                                                                                  
[PRIOTREE] path=interfaces ethernet eth0 prio=318 isValue=1 isTag=1                                                                               
[PRIOTREE] path=interfaces l2tpv3 l2tpeth333 prio=485 isValue=1 isTag=1                                                                           
[PRIOTREE] path=interfaces loopback lo prio=300 isValue=1 isTag=1                                                                                 
[PRIOTREE] path=protocols static prio=480 isValue=0 isTag=0                                                                                       
[PRIOPUSH] path= prio=0 state=0 numChildren=5 queue=pq                                                                                            
[PRIOPUSH] path=interfaces bridge br0 prio=319 state=1 numChildren=0 queue=pq                                                                     
[PRIOPUSH] path=interfaces ethernet eth0 prio=318 state=0 numChildren=0 queue=pq                                                                  
[PRIOPUSH] path=interfaces l2tpv3 l2tpeth333 prio=485 state=1 numChildren=0 queue=pq                                                              
[PRIOPUSH] path=interfaces loopback lo prio=300 state=0 numChildren=0 queue=pq                                                                    
[PRIOPUSH] path=protocols static prio=480 state=1 numChildren=0 queue=pq                                                                          
[PRIOQUEUE] Popping path= prio=0                                                                                                                  
[PRIOQUEUE] Popping path=interfaces loopback lo prio=300                                                                                          
[PRIOQUEUE] Popping path=interfaces ethernet eth0 prio=318                                                                                        
[PRIOQUEUE] Popping path=interfaces bridge br0 prio=319                                                                                           
[PRIOQUEUE] Popping path=protocols static prio=480                                                                                                
[PRIOQUEUE] Popping path=interfaces l2tpv3 l2tpeth333 prio=485
[EXECNODE] path= state=0 subtreeChanged=1
[EXECNODE] path=interfaces loopback lo state=0 subtreeChanged=1
[EXECNODE] path=interfaces ethernet eth0 state=0 subtreeChanged=1
[EXECNODE] path=interfaces bridge br0 state=1 subtreeChanged=1
[EXECNODE] path=protocols static state=1 subtreeChanged=1
[EXECNODE] path=interfaces l2tpv3 l2tpeth333 state=1 subtreeChanged=1

The same issue reproduces on 1.4.4 as well, it is not unique to 1.5.0:

[   42.811157] vyos-router[1163]: Waiting for NICs to settle down: settled in 0sec..
[   52.471547] vyos-router[1163]: Mounting VyOS Config...done.
[   89.262781] vyos-router[1163]: Starting VyOS router: migrate configure.
[   89.507114] vyos-config[1169]: Configuration success

Welcome to VyOS - vyos ttyS0

vyos login: vyos
Password: 
Welcome to VyOS!

   ┌── ┐
   . VyOS 1.4.4
   └ ──┘  sagitta

 * Documentation:  https://docs.vyos.io/en/sagitta
 * Project news:   https://blog.vyos.io
 * Bug reports:    https://vyos.dev

You can change this banner using "set system login banner post-login" command.

VyOS is a free software distribution that includes multiple components,
you can check individual component licenses under /usr/share/doc/*/copyright

vyos@vyos:~$ conf
[edit]
vyos@vyos# set interfaces ethernet eth0 address '10.10.10.1/24'
[edit]
vyos@vyos# set interfaces loopback lo address '192.168.1.11/32'
[edit]
vyos@vyos# set interfaces bridge br0 member interface eth3
[edit]
vyos@vyos# set interfaces bridge br0 member interface l2tpeth333
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 encapsulation 'ip'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 peer-session-id '33'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 peer-tunnel-id '33'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 remote '198.51.100.100'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 session-id '33'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 source-address '192.168.1.11'
[edit]
vyos@vyos# set interfaces l2tpv3 l2tpeth333 tunnel-id '33'
[edit]
vyos@vyos# set protocols static route 198.51.100.0/24 next-hop 10.10.10.2
[edit]
vyos@vyos# commit
[ interfaces l2tpv3 l2tpeth333 ]
VyOS had an issue completing a command.

We are sorry that you encountered a problem while using VyOS.
There are a few things you can do to help us (and yourself):
- Contact us using the online help desk if you have a subscription:
  https://support.vyos.io/
- Make sure you are running the latest version of VyOS available at:
  https://vyos.net/get/
- Consult the community forum to see how to handle this issue:
  https://forum.vyos.io
- Join us on Slack where our users exchange help and advice:
  https://vyos.slack.com

When reporting problems, please include as much information as possible:
- do not obfuscate any data (feel free to contact us privately if your 
  business policy requires it)
- and include all the information presented below

Report time:      2026-05-03 15:07:58
Image version:    VyOS 1.4.4
Release train:    sagitta

Built by:         autobuild@vyos.net
Built on:         Thu 18 Dec 2025 16:20 UTC
Build UUID:       a19109d0-ec1c-48ec-b239-14cd7a27926e
Build commit ID:  f2bd2fba602ba5

Architecture:     x86_64
Boot via:         installed image
System type:      KVM guest

Hardware vendor:  QEMU
Hardware model:   Standard PC (i440FX + PIIX, 1996)
Hardware S/N:     
Hardware UUID:    e828f6a5-d21e-4902-b0e9-00a08e16bb03

Traceback (most recent call last):
  File "/usr/libexec/vyos/conf_mode/interfaces_l2tpv3.py", line 109, in <module>
    apply(c)
  File "/usr/libexec/vyos/conf_mode/interfaces_l2tpv3.py", line 98, in apply
    l = L2TPv3If(**l2tpv3)
        ^^^^^^^^^^^^^^^^^^
  File "/usr/lib/python3/dist-packages/vyos/ifconfig/interface.py", line 345, in __init__
    self._create()
  File "/usr/lib/python3/dist-packages/vyos/ifconfig/l2tpv3.py", line 76, in _create
    self._cmd(cmd.format(**self.config))
  File "/usr/lib/python3/dist-packages/vyos/ifconfig/control.py", line 54, in _cmd
    return cmd(command, self.debug)
           ^^^^^^^^^^^^^^^^^^^^^^^^
  File "/usr/lib/python3/dist-packages/vyos/utils/process.py", line 155, in cmd
    raise OSError(code, feedback)
FileNotFoundError: [Errno 2] failed to run command: ip l2tp add session name l2tpeth333 tunnel_id 33 session_id 33 peer_session_id 33
returned: 
exit code: 2

noteworthy:
returned (out):

returned (err):
RTNETLINK answers: Network is unreachable
cmd 'ip l2tp add tunnel tunnel_id 33 peer_tunnel_id 33 udp_sport 5000 udp_dport 5000 encap ip local 192.168.1.11 remote 198.51.100.100'
returned (out):

returned (err):
RTNETLINK answers: Network is unreachable
cmd 'ip l2tp add tunnel tunnel_id 33 peer_tunnel_id 33 udp_sport 5000 udp_dport 5000 encap ip local 192.168.1.11 remote 198.51.100.100'
returned (out):

returned (err):
RTNETLINK answers: Network is unreachable
cmd 'ip l2tp add tunnel tunnel_id 33 peer_tunnel_id 33 udp_sport 5000 udp_dport 5000 encap ip local 192.168.1.11 remote 198.51.100.100'
returned (out):

returned (err):
RTNETLINK answers: Network is unreachable
cmd 'ip l2tp add tunnel tunnel_id 33 peer_tunnel_id 33 udp_sport 5000 udp_dport 5000 encap ip local 192.168.1.11 remote 198.51.100.100'
returned (out):

returned (err):
RTNETLINK answers: Network is unreachable
cmd 'ip l2tp add tunnel tunnel_id 33 peer_tunnel_id 33 udp_sport 5000 udp_dport 5000 encap ip local 192.168.1.11 remote 198.51.100.100'
returned (out):

returned (err):
RTNETLINK answers: Network is unreachable
cmd 'ip l2tp add session name l2tpeth333 tunnel_id 33 session_id 33 peer_session_id 33'
returned (out):

returned (err):
RTNETLINK answers: No such device

[[interfaces l2tpv3 l2tpeth333]] failed
Commit failed
[edit]

The kernel needs a reachable route toward remote consistent with local (same routing domain / correct egress). If not, rtnetlink typically returns “Network is unreachable” (ENETUNREACH).

a.kudientsov renamed this task from L2TPv3 broken in Circinus to L2TPv3: tunnel creation fails if the route to remote is added in the same commit.May 14 2026, 7:24 AM
a.kudientsov changed the task status from Open to In progress.
a.kudientsov changed Version from 1.5.0 to 1.5.0, 1.4.4.
Viacheslav changed the task status from In progress to Needs testing.Jun 29 2026, 10:42 AM