Route-based IPsec VTI interfaces are xfrm interfaces. Their kernel operstate is unknown whether or not the CHILD_SA is established. The built-in service monitoring prometheus node-exporter therefore exports node_network_up{device="vtiX"} 0 for healthy tunnels. The node_exporter up metric is operstate == "up". Monitoring built on the standard node-exporter metrics cannot tell an established VTI from a down one, even though VyOS itself (show interfaces) shows u/u.
Steps to reproduce
- Configure a site-to-site peer with vti bind vti1 and bring the tunnel up (show vpn ipsec sa → up).
- set service monitoring prometheus node-exporter listen-address <local-ip>, then commit.
- Inspect the interface and the exported metrics.
Observed (tunnel established and carrying traffic)
$ show interfaces vti vti1 10.255.255.1/30 u/u IPsec to SITE-B $ ip -d link show vti1 9: vti1@NONE: <NOARP,UP,LOWER_UP> mtu 1436 qdisc noqueue state UNKNOWN mode DEFAULT group default qlen 1000 link/none ... xfrm if_id 0x2 ... $ cat /sys/class/net/vti1/operstate unknown node_network_up{device="vti1"} 0 node_network_carrier{device="vti1"} 1 node_network_info{adminstate="up",device="vti1",operstate="unknown",...} 1 node_network_up{device="eth0"} 1
Expected / desired
The VTI's operational state should follow the IPsec CHILD_SA (up when installed, down/dormant when not). Then node_network_up, SNMP ifOperStatus and anything else that reads operstate would reflect tunnel health.
Notes / possible approach
- unknown is standard kernel behaviour for virtual devices without link-state reporting, so this is not a kernel bug. VyOS, however, already knows the SA state: vti-up-down runs on CHILD_SA up/down and toggles the interface admin state (Interface vti1 up-client ..., Interface vti1 is admin up).
- A possible improvement: create the interface in dormant link mode and let vti-up-down set the operstate to UP/DORMANT via netlink (IFLA_OPERSTATE), as some tunnel daemons do. RFC 2863-aware tools (node_exporter, SNMP IF-MIB) would then report the real tunnel state.
- At minimum, a note in the docs would help (e.g. "monitor VTI health via node_network_info{adminstate} or probes, not node_network_up").
Current workaround
Monitor tunnels with blackbox-exporter ICMP probes across the VTI (probe_success), or with node_network_info{adminstate="up"}.