The system is supposed to reject IKE/ESP proposals that use encryption algorithms unsupported by VPP's IPsec acceleration. In practice, the flag that gates this check (vpp_ipsec_exists) is computed from a config path that no longer exists. Incompatible algorithms are silently accepted even when VPP IPsec acceleration is enabled.
Steps to reproduce
configure set vpp settings ipsec-acceleration set vpn ipsec esp-group ESP-TEST proposal 1 encryption 3des set vpn ipsec esp-group ESP-TEST proposal 1 hash sha256 set vpn ipsec ike-group IKE-TEST proposal 1 encryption serpent128 set vpn ipsec ike-group IKE-TEST proposal 1 hash sha256 set vpn ipsec ike-group IKE-TEST proposal 1 dh-group 14 set vpn ipsec authentication psk PSK1 id R1 set vpn ipsec authentication psk PSK1 id R2 set vpn ipsec authentication psk PSK1 secret testsecret123 set vpn ipsec site-to-site peer PEER1 authentication mode pre-shared-secret set vpn ipsec site-to-site peer PEER1 authentication local-id R1 set vpn ipsec site-to-site peer PEER1 authentication remote-id R2 set vpn ipsec site-to-site peer PEER1 ike-group IKE-TEST set vpn ipsec site-to-site peer PEER1 local-address 10.10.1.1 set vpn ipsec site-to-site peer PEER1 remote-address 12.10.2.1 set vpn ipsec site-to-site peer PEER1 tunnel 1 esp-group ESP-TEST set vpn ipsec site-to-site peer PEER1 tunnel 1 local prefix 10.10.1.0/24 set vpn ipsec site-to-site peer PEER1 tunnel 1 remote prefix 12.10.2.0/24 commit
3des and serpent128 is not in the allow-list
Expected:
commit should fail with a error about an incompatible encryption algorithm for VPP IPsec
Actual result
commit succeeds