Page MenuHomeVyOS Platform

VTI (xfrm) interfaces always report operstate UNKNOWN — Prometheus `node_network_up` is 0 for every VTI even when the tunnel is up
Open, Requires assessmentPublicFEATURE REQUEST

Description

Route-based IPsec VTI interfaces are xfrm interfaces. Their kernel operstate is unknown whether or not the CHILD_SA is established. The built-in service monitoring prometheus node-exporter therefore exports node_network_up{device="vtiX"} 0 for healthy tunnels. The node_exporter up metric is operstate == "up". Monitoring built on the standard node-exporter metrics cannot tell an established VTI from a down one, even though VyOS itself (show interfaces) shows u/u.

Steps to reproduce

  1. Configure a site-to-site peer with vti bind vti1 and bring the tunnel up (show vpn ipsec sa → up).
  2. set service monitoring prometheus node-exporter listen-address <local-ip>, then commit.
  3. Inspect the interface and the exported metrics.

Observed (tunnel established and carrying traffic)

$ show interfaces vti
vti1             10.255.255.1/30                   u/u  IPsec to SITE-B

$ ip -d link show vti1
9: vti1@NONE: <NOARP,UP,LOWER_UP> mtu 1436 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000
    link/none ...
    xfrm if_id 0x2 ...

$ cat /sys/class/net/vti1/operstate
unknown

node_network_up{device="vti1"} 0
node_network_carrier{device="vti1"} 1
node_network_info{adminstate="up",device="vti1",operstate="unknown",...} 1
node_network_up{device="eth0"} 1

Expected / desired

The VTI's operational state should follow the IPsec CHILD_SA (up when installed, down/dormant when not). Then node_network_up, SNMP ifOperStatus and anything else that reads operstate would reflect tunnel health.

Notes / possible approach

  • unknown is standard kernel behaviour for virtual devices without link-state reporting, so this is not a kernel bug. VyOS, however, already knows the SA state: vti-up-down runs on CHILD_SA up/down and toggles the interface admin state (Interface vti1 up-client ..., Interface vti1 is admin up).
  • A possible improvement: create the interface in dormant link mode and let vti-up-down set the operstate to UP/DORMANT via netlink (IFLA_OPERSTATE), as some tunnel daemons do. RFC 2863-aware tools (node_exporter, SNMP IF-MIB) would then report the real tunnel state.
  • At minimum, a note in the docs would help (e.g. "monitor VTI health via node_network_info{adminstate} or probes, not node_network_up").

Current workaround

Monitor tunnels with blackbox-exporter ICMP probes across the VTI (probe_success), or with node_network_info{adminstate="up"}.

Details

Version
VyOS 2026.03 (Stream, circinus)
Is it a breaking change?
Perfectly compatible
Issue type
Feature (new functionality)