Page MenuHomeVyOS Platform

The feature disable-route-autoinstall does not take effect until IPSec is restarted
Open, NormalPublicBUG

Description

Enabling or disabling disable-route-autoinstall does not take effect while the IPSec daemon is not restarted
The command set vpn ipsec option disable-route-autoinstall prevents installing routes in the routing table 220 based on IPSec policies.
But after applying this command, the existing routes in table 220 are not cleared. Also, the new connections and new peer configurations continue adding routes into the routing table 220.
Only restarting IPSec (strongswan) daemon fixes this situation.
I tried to use swanctl --reload-settings and terminate sessions, but it did not help
There can be 2 ways to resolve this issue.

  1. Find the solution to fix it
  2. Add a Warning message that there is a need to restart ipsec.

Details

Version
VyOS 2026.07.21-1151-rolling, VyOS 1.5.0-S1, VyOS 1.4.4-S2
Is it a breaking change?
Perfectly compatible
Issue type
Bug (incorrect behavior)

Event Timeline

a.apostoliuk triaged this task as Normal priority.