If the set vpn ipsec option disable-route-autoinstall command is not configured, Strongswan adds routes to table 220 based on peer policies.
If the peer is configured with connection-type trap, Strongswan adds routes to table 220 immediately after configuration.
But when I try to disable the peer using the command set vpn ipsec site-to-site peer TEST disable, I face the following problems.
- The routes that are related to this peer are not cleared from table 220.
- I observe that traffic that matches peer policies is encrypted. BUT this peer is disabled.
Expected behavior: After disabling the peer, all routes associated with the peer's policies should be cleared.
The traffic should not be encrypted.