Page MenuHomeVyOS Platform

Unexpected behavior when disabling IPSec peer with connection-type trap
Open, NormalPublicBUG

Description

If the set vpn ipsec option disable-route-autoinstall command is not configured, Strongswan adds routes to table 220 based on peer policies.
If the peer is configured with connection-type trap, Strongswan adds routes to table 220 immediately after configuration.
But when I try to disable the peer using the command set vpn ipsec site-to-site peer TEST disable, I face the following problems.

  1. The routes that are related to this peer are not cleared from table 220.
  2. I observe that traffic that matches peer policies is encrypted. BUT this peer is disabled.

Expected behavior: After disabling the peer, all routes associated with the peer's policies should be cleared.
The traffic should not be encrypted.

Details

Version
VyOS 2026.07.21-1151-rolling, VyOS 1.5.0-S1, VyOS 1.4.4-S2
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)

Event Timeline

a.apostoliuk triaged this task as Normal priority.

About point 2.

I observe that traffic that matches peer policies is encrypted. BUT this peer is disabled.

If I execute sudo swanctl -L , it shows nothing. But if I execute sudo ip xfrm policy, it shows polices, that were disabled in the configuration.