Page MenuHomeVyOS Platform

Can not disable VTI interface
Open, NormalPublicBUG

Description

Cannot disable VTI interface
Configuration:
R1:

vyos@vyos:~$ show configuration commands
set interfaces ethernet eth0 address '10.0.0.1/30'
set interfaces vti vti1 address '10.10.10.1/30'
set vpn ipsec authentication psk TEST id '10.0.0.2'
set vpn ipsec authentication psk TEST id '10.0.0.1'
set vpn ipsec authentication psk TEST secret 'test'
set vpn ipsec esp-group TEST-ESP pfs 'disable'
set vpn ipsec esp-group TEST-ESP proposal 1 encryption 'aes256'
set vpn ipsec esp-group TEST-ESP proposal 1 hash 'sha1'
set vpn ipsec ike-group TEST-IKE close-action 'start'
set vpn ipsec ike-group TEST-IKE dead-peer-detection action 'restart'
set vpn ipsec ike-group TEST-IKE dead-peer-detection interval '30'
set vpn ipsec ike-group TEST-IKE key-exchange 'ikev2'
set vpn ipsec ike-group TEST-IKE proposal 1 dh-group '19'
set vpn ipsec ike-group TEST-IKE proposal 1 encryption 'aes256'
set vpn ipsec ike-group TEST-IKE proposal 1 hash 'sha512'
set vpn ipsec interface 'eth0'
set vpn ipsec options disable-route-autoinstall
set vpn ipsec site-to-site peer TEST authentication local-id '10.0.0.1'
set vpn ipsec site-to-site peer TEST authentication mode 'pre-shared-secret'
set vpn ipsec site-to-site peer TEST authentication remote-id '10.0.0.2'
set vpn ipsec site-to-site peer TEST connection-type 'initiate'
set vpn ipsec site-to-site peer TEST default-esp-group 'TEST-ESP'
set vpn ipsec site-to-site peer TEST ike-group 'TEST-IKE'
set vpn ipsec site-to-site peer TEST local-address '10.0.0.1'
set vpn ipsec site-to-site peer TEST remote-address '10.0.0.2'
set vpn ipsec site-to-site peer TEST vti bind 'vti1'

R2:

set interfaces ethernet eth0 address '10.0.0.2/30'
set interfaces vti vti1 address '10.10.10.2/30'
set vpn ipsec authentication psk TEST id '10.0.0.1'
set vpn ipsec authentication psk TEST id '10.0.0.2'
set vpn ipsec authentication psk TEST secret 'test'
set vpn ipsec esp-group TEST-ESP pfs 'disable'
set vpn ipsec esp-group TEST-ESP proposal 1 encryption 'aes256'
set vpn ipsec esp-group TEST-ESP proposal 1 hash 'sha1'
set vpn ipsec ike-group TEST-IKE close-action 'trap'
set vpn ipsec ike-group TEST-IKE dead-peer-detection action 'trap'
set vpn ipsec ike-group TEST-IKE dead-peer-detection interval '30'
set vpn ipsec ike-group TEST-IKE key-exchange 'ikev2'
set vpn ipsec ike-group TEST-IKE proposal 1 dh-group '19'
set vpn ipsec ike-group TEST-IKE proposal 1 encryption 'aes256'
set vpn ipsec ike-group TEST-IKE proposal 1 hash 'sha512'
set vpn ipsec interface 'eth0'
set vpn ipsec options disable-route-autoinstall
set vpn ipsec site-to-site peer TEST authentication local-id '10.0.0.2'
set vpn ipsec site-to-site peer TEST authentication mode 'pre-shared-secret'
set vpn ipsec site-to-site peer TEST authentication remote-id '10.0.0.1'
set vpn ipsec site-to-site peer TEST connection-type 'respond'
set vpn ipsec site-to-site peer TEST default-esp-group 'TEST-ESP'
set vpn ipsec site-to-site peer TEST ike-group 'TEST-IKE'
set vpn ipsec site-to-site peer TEST local-address '10.0.0.2'
set vpn ipsec site-to-site peer TEST remote-address '10.0.0.1'
set vpn ipsec site-to-site peer TEST vti bind 'vti1'

IPSec tunnel is up and working
From R1:

PING 10.10.10.2 (10.10.10.2) 56(84) bytes of data.
64 bytes from 10.10.10.2: icmp_seq=1 ttl=64 time=0.091 ms
64 bytes from 10.10.10.2: icmp_seq=2 ttl=64 time=0.083 ms

Try to disable the vti interface on R1:

set interfaces vti vti1 disable
commit

Results:

vyos@vyos:~$ show interfaces
Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down
Interface    IP Address     MAC                VRF        MTU  S/L    Description
-----------  -------------  -----------------  -------  -----  -----  -------------
eth0         10.0.0.1/30    0c:91:af:95:00:00  default   1500  u/u
eth1         -              0c:91:af:95:00:01  default   1500  u/D
eth2         -              0c:91:af:95:00:02  default   1500  u/D
eth3         -              0c:91:af:95:00:03  default   1500  u/D
eth4         -              0c:91:af:95:00:04  default   1500  u/D
eth5         -              0c:91:af:95:00:05  default   1500  u/D
lo           127.0.0.1/8    00:00:00:00:00:00  default  65536  u/u
             ::1/128
vti1         10.10.10.1/30  n/a                default   1500  u/u
vyos@vyos:~$ show vpn ipsec sa
Connection    State    Uptime    Bytes In/Out    Packets In/Out    Remote address    Remote ID    Proposal
------------  -------  --------  --------------  ----------------  ----------------  -----------  ------------------------
TEST-vti      up       8m4s      504B/504B       6/6               10.0.0.2          10.0.0.2     AES_CBC_256/HMAC_SHA1_96
vyos@vyos:~$ ping 10.10.10.2
PING 10.10.10.2 (10.10.10.2) 56(84) bytes of data.
64 bytes from 10.10.10.2: icmp_seq=1 ttl=64 time=1.94 ms
64 bytes from 10.10.10.2: icmp_seq=2 ttl=64 time=0.759 ms
^C
--- 10.10.10.2 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1002ms
rtt min/avg/max/mdev = 0.759/1.350/1.942/0.591 ms

Expected behavior:
Interface vti1 should be in A/D state
Traffic should not pass via vti interface.

This problem exist on 1.4.5 only. I tested on 1.5.1 - everything is ok.

Details

Version
VyOS 1.4.5
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)

Event Timeline

a.apostoliuk triaged this task as Normal priority.

The status changes only if the system is rebooted. The situation is the same in the opposite direction. After rebooting, I cannot bring up the disabled vti interface.