Page MenuHomeVyOS Platform

VPP IPsec algorithm-compatibility check ignored
Closed, ResolvedPublicBUG

Description

The system is supposed to reject IKE/ESP proposals that use encryption algorithms unsupported by VPP's IPsec acceleration. In practice, the flag that gates this check (vpp_ipsec_exists) is computed from a config path that no longer exists. Incompatible algorithms are silently accepted even when VPP IPsec acceleration is enabled.
Steps to reproduce

configure
set vpp settings ipsec-acceleration

set vpn ipsec esp-group ESP-TEST proposal 1 encryption 3des
set vpn ipsec esp-group ESP-TEST proposal 1 hash sha256

set vpn ipsec ike-group IKE-TEST proposal 1 encryption serpent128
set vpn ipsec ike-group IKE-TEST proposal 1 hash sha256
set vpn ipsec ike-group IKE-TEST proposal 1 dh-group 14

set vpn ipsec authentication psk PSK1 id R1
set vpn ipsec authentication psk PSK1 id R2
set vpn ipsec authentication psk PSK1 secret testsecret123

set vpn ipsec site-to-site peer PEER1 authentication mode pre-shared-secret
set vpn ipsec site-to-site peer PEER1 authentication local-id R1
set vpn ipsec site-to-site peer PEER1 authentication remote-id R2
set vpn ipsec site-to-site peer PEER1 ike-group IKE-TEST
set vpn ipsec site-to-site peer PEER1 local-address 10.10.1.1
set vpn ipsec site-to-site peer PEER1 remote-address 12.10.2.1
set vpn ipsec site-to-site peer PEER1 tunnel 1 esp-group ESP-TEST
set vpn ipsec site-to-site peer PEER1 tunnel 1 local prefix 10.10.1.0/24
set vpn ipsec site-to-site peer PEER1 tunnel 1 remote prefix 12.10.2.0/24
commit

3des and serpent128 is not in the allow-list

Expected:

commit should fail with a error about an incompatible encryption algorithm for VPP IPsec

Actual result

commit succeeds

Details

Version
2026.09.09-0029-rolling
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)