Accel-ppp restart triggered after any vpn l2tp commit has surfaced an issue with frr/zebra where it doesn't always catch the rename and ends up with routes pointing toward the pppX interface that no-longer exists.
accel-ppp creates the session device as pppN, then renames it to l2tpN. zebra sometimes creates a second interface entry rather than processing the rename, and whichever entry receives the subsequent RTM_NEWADDR keeps the address. The result is a /32 in show ip route bound to an interface that does not exist in ip link at all.
if you terminate the l2tp session and let the client reconnecton its own, the netlink device rename race seems to happen every time.
l2tp0 up default 101.127.0.1/32
the user associated with l2tp0 connected once and has stayed connected. this lines up with the kernel routing table:
206.113.200.4 dev l2tp0 proto kernel scope link src 101.127.0.1
the l2tp1 user is the same on initial connect:
l2tp1 up default 101.127.0.1/32 ... 206.99.34.1 dev l2tp1 proto kernel scope link src 101.127.0.1
bumping the session on the vyos side to force pppoe connection reinitiate for the l2tp1 user, it comes back, but when it comes back there is now both l2tp1 with no associated default route in FRR, and a ppp0 interface with the valid route. here is where the breakdown happens: now frr sees l2tp1 with no route, and ppp0 with a route:
l2tp1 up default ... ppp0 up default 101.127.0.1/32.
the linux kernel only has l2tp1 with the route:
206.99.34.1 dev l2tp1 proto kernel scope link src 101.127.0.1
there is no kernel route for ppp0 anymore, zebra is now out-of-sync.
Configuration:
set vpn l2tp remote-access authentication mode 'radius' set vpn l2tp remote-access authentication radius server 206.11.192.19 key '' set vpn l2tp remote-access authentication radius server 206.11.192.27 key '' set vpn l2tp remote-access client-ip-pool modem-mgmt range '172.16.33.0/24' set vpn l2tp remote-access gateway-address '101.127.0.1' set vpn l2tp remote-access lns host-name 'lns01' set vpn l2tp remote-access mtu '1508' set vpn l2tp remote-access name-server '214.23.130.1' set vpn l2tp remote-access name-server '214.23.131.1' set vpn l2tp remote-access ppp-options disable-ccp set vpn l2tp remote-access ppp-options mru '1508'
Comment the ifname option in /usr/share/vyos/templates/accel-ppp/l2tp.config.j2, fixes the issue:
[l2tp]
verbose=1
#ifname=l2tp%d
ppp-max-mtu={{ mtu }}
mppe={{ ppp_options.mppe }}