Page MenuHomeVyOS Platform

Strongswan 5.x can not create a route when using a point-to-point tunnel (policy routing)
Closed, ResolvedPublicBUG

Description

Version:

Version:          VyOS 20260519
Release train:    current
Release flavor:   generic

Built by:         batman@flexcoders.dev
Built on:         Tue 19 May 2026 16:43 UTC
Build UUID:       8831142c-2bf5-4b77-900a-b62398321a33
Build commit ID:  440a78d5e423e4

Config:

set vpn ipsec interface pppoe0
set vpn ipsec ike-group IKE1 close-action start
set vpn ipsec ike-group IKE1 key-exchange ikev1
set vpn ipsec ike-group IKE1 lifetime 7800
set vpn ipsec ike-group IKE1 dead-peer-detection timeout 60
set vpn ipsec ike-group IKE1 dead-peer-detection action restart
set vpn ipsec ike-group IKE1 dead-peer-detection interval 15
set vpn ipsec ike-group IKE1 proposal 1 dh-group 5
set vpn ipsec ike-group IKE1 proposal 1 encryption aes256
set vpn ipsec ike-group IKE1 proposal 1 hash md5
set vpn ipsec ike-group IKE1 proposal 1 prf prfmd5
set vpn ipsec esp-group ESP1 lifetime 3600
set vpn ipsec esp-group ESP1 mode tunnel
set vpn ipsec esp-group ESP1 pfs disable
set vpn ipsec esp-group ESP1 proposal 1 encryption aes256
set vpn ipsec esp-group ESP1 proposal 1 hash md5
set vpn ipsec esp-group ESP1 compression
set vpn ipsec authentication psk PEER1 id 'firewall.xxxxxx'
set vpn ipsec authentication psk PEER1 secret-type plaintext
set vpn ipsec authentication psk PEER1 secret 'xxxxxxxx'
set vpn ipsec site-to-site peer PEER1 authentication mode pre-shared-secret
set vpn ipsec site-to-site peer PEER1 authentication local-id 'srvr2.xxxxxxx'
set vpn ipsec site-to-site peer PEER1 authentication remote-id 'firewall.xxxxxx'
set vpn ipsec site-to-site peer PEER1 local-address 'x.x.x.x'
set vpn ipsec site-to-site peer PEER1 remote-address 'x.x.x.x'
set vpn ipsec site-to-site peer PEER1 connection-type initiate
set vpn ipsec site-to-site peer PEER1 ike-group IKE1
set vpn ipsec site-to-site peer PEER1 default-esp-group ESP1
set vpn ipsec site-to-site peer PEER1 tunnel 0 local prefix 172.19.0.0/20
set vpn ipsec site-to-site peer PEER1 tunnel 1 local prefix fdfd:dead:beef:cafe:0:1::/108
set vpn ipsec site-to-site peer PEER1 tunnel 0 remote prefix 172.18.0.0/16
set vpn ipsec site-to-site peer PEER1 tunnel 1 remote prefix fdfd:dead:beef:cafe::/96

Results in

May 29 15:12:15 charon[10793]: 05[KNL] <PEER1|3> received netlink error: Nexthop has invalid gateway (101)
May 29 15:12:15 charon[10793]: 05[KNL] <PEER1|3> unable to install source route for 172.19.9.1

Issue is reported here https://github.com/strongswan/strongswan/issues/2548 and fixed in Strongswan 6.0.5.

Given the fact Debian 12 is targeted for 1.5 LTS, maybe Strongswan needs upgrading, or alternatively, this fix backported.

I can confirm that the workaround stated in the github issue, manually adding the route, does work around the issue, but not an option for production systems in remote or mobile locations.

Details

Version
1.5-rolling 20260519
Is it a breaking change?
Perfectly compatible
Issue type
Bug (incorrect behavior)
Forum thread
https://forum.vyos.io/t/ipsec-site-to-site-no-routes-created

Related Objects

Event Timeline

There is a second reason for the upgrade: there is a memory leak in Strongswan, at least in the case I'm using it in (IKEv1 over PPPoE).

See https://forum.vyos.io/t/oom-killer-crashes-memory-leak/17486 for details.

To add, sudo systemctl stop strongswan followed by a sudo systemctl start strongswan doesn't release the memory claimed.

Which means I have to reboot at least once every 18 hours. Going to add a bit more memory tomorrow so I can stretch it to once every 24 hours (don't fancy getting out of bed to do so).

Hopefully resolved by upgrading to Strongswan 6.0.6.
Could you please check latest rolling release?
Thank you.

Thanks.

I'll have to think about how to test this now, we migrated the last Sophos UTM over the weekend, after which we migrated all tunnels from IPSec to wireguard.

Viacheslav changed the task status from Open to Needs testing.Jun 25 2026, 1:08 PM
Viacheslav subscribed.

We have upgraded the Strongswan to 6.x
Open a new bug report if you have similar/any issues