After deep testing, we saw that if we reset the peer on the initiator side, strongswan does not reinitiate the connection by itself.
Need to add a connection initiation in the reset function on the initiator side.
- Feed Queries
- All Stories
- Search
- Feed Search
- Transactions
- Transaction Logs
Feed Search
Jul 2 2024
Jul 2 2024
Jun 19 2024
Jun 19 2024
a.apostoliuk added a comment to T6148: Reset vpn ipsec command breaks tunnel and does not reset SAs that are down.
a.apostoliuk changed the status of T6148: Reset vpn ipsec command breaks tunnel and does not reset SAs that are down from Open to In progress.
a.apostoliuk edited projects for T6148: Reset vpn ipsec command breaks tunnel and does not reset SAs that are down, added: VyOS 1.4 Sagitta (1.4.1); removed VyOS 1.4 Sagitta.
a.apostoliuk moved T6148: Reset vpn ipsec command breaks tunnel and does not reset SAs that are down from In Progress to Open on the VyOS 1.4 Sagitta board.
a.apostoliuk moved T6148: Reset vpn ipsec command breaks tunnel and does not reset SAs that are down from Finished to In Progress on the VyOS 1.4 Sagitta board.
May 22 2024
May 22 2024
a.apostoliuk changed the status of T6359: Multicast does not forward after reboot from In progress to Needs testing.
May 17 2024
May 17 2024
a.apostoliuk changed the status of T6359: Multicast does not forward after reboot from Open to In progress.
a.apostoliuk changed the status of T6157: Can not create two GRE tunnels to the same DST but from different SRC addresses from In progress to Open.
May 9 2024
May 9 2024
May 3 2024
May 3 2024
a.apostoliuk added a comment to T6300: [1.3->1.4 Migration] An empty interface configuration drops all interfaces configuration.
I think the problem is similar to https://vyos.dev/T5611
a.apostoliuk triaged T6300: [1.3->1.4 Migration] An empty interface configuration drops all interfaces configuration as High priority.
May 2 2024
May 2 2024
a.apostoliuk changed the status of T6273: Hyphens and underscores are considered invalid in PPPoE access-concentrator names from In progress to Needs testing.
a.apostoliuk changed the status of T6272: PPPoE configuration does not load after deleting a PPPoE interface from the system from In progress to Needs testing.
Apr 30 2024
Apr 30 2024
a.apostoliuk updated the task description for T6283: Cannot delete as-path prepend from policy when it contains more than one AS.
a.apostoliuk lowered the priority of T6283: Cannot delete as-path prepend from policy when it contains more than one AS from High to Normal.
a.apostoliuk triaged T6283: Cannot delete as-path prepend from policy when it contains more than one AS as High priority.
Apr 29 2024
Apr 29 2024
a.apostoliuk changed the status of T6272: PPPoE configuration does not load after deleting a PPPoE interface from the system from Open to In progress.
a.apostoliuk changed the status of T6273: Hyphens and underscores are considered invalid in PPPoE access-concentrator names from Open to In progress.
Apr 26 2024
Apr 26 2024
a.apostoliuk triaged T6272: PPPoE configuration does not load after deleting a PPPoE interface from the system as High priority.
Apr 15 2024
Apr 15 2024
Apr 12 2024
Apr 12 2024
a.apostoliuk added a comment to T6148: Reset vpn ipsec command breaks tunnel and does not reset SAs that are down.
After considering, we decided that reset is the same as terminate.
If you want to add a feature start manual initialization, please create a feature request.
a.apostoliuk added a comment to T6148: Reset vpn ipsec command breaks tunnel and does not reset SAs that are down.
In 1.4 and 1.5 command reset vpn ipsec has a termination meaning.
Apr 11 2024
Apr 11 2024
a.apostoliuk changed the status of T3437: BGP Confederation Addition Causes Error from Confirmed to Needs testing.
a.apostoliuk added a comment to T3770: BGP neighbor not generating the correct frr configuration when moved to peer-group.
You can use the next type of configuration
set protocols bgp 4200010000 neighbor 2001:db8::2 address-family ipv6-unicast peer-group 'CUST_CR_IPV6' set protocols bgp 4200010000 parameters default no-ipv4-unicast set protocols bgp 4200010000 peer-group CUST_CR_IPV6 address-family ipv6-unicast set protocols bgp 4200010000 peer-group CUST_CR_IPV6 remote-as '65500'
But we recommend to check the result in FRR configuration.
Apr 10 2024
Apr 10 2024
Apr 8 2024
Apr 8 2024
Rechecked - The issue exists.
a.apostoliuk changed the status of T6196: route-map and summary-only do not work in BGP aggregation at the same time from Unknown Status to Resolved.
a.apostoliuk moved T6197: Validation error in the IPoE server interface client-subnet option from Open to Finished on the VyOS 1.5 Circinus board.
a.apostoliuk changed the status of T6197: Validation error in the IPoE server interface client-subnet option from In progress to Needs testing.
Apr 5 2024
Apr 5 2024
I do not see this issue in 1.3.6
a.apostoliuk triaged T6205: ipoe: error in migration script logic while renaming mac-address to mac as High priority.
Apr 4 2024
Apr 4 2024
a.apostoliuk changed the status of T6157: Can not create two GRE tunnels to the same DST but from different SRC addresses from Open to In progress.
Apr 3 2024
Apr 3 2024
a.apostoliuk changed the status of T6197: Validation error in the IPoE server interface client-subnet option from Open to In progress.
a.apostoliuk changed the status of T6196: route-map and summary-only do not work in BGP aggregation at the same time from Resolved to Unknown Status.
Apr 2 2024
Apr 2 2024
a.apostoliuk changed the status of T6150: Impossible to set a static IP address via RADIUS in IPoE from In progress to Needs testing.
Apr 1 2024
Apr 1 2024
a.apostoliuk triaged T6196: route-map and summary-only do not work in BGP aggregation at the same time as Normal priority.
a.apostoliuk changed the status of T6196: route-map and summary-only do not work in BGP aggregation at the same time from Open to In progress.
Mar 22 2024
Mar 22 2024
a.apostoliuk moved T6130: [1.3.6->1.4.0-epa2 Migration] BGP "set community" missing from Open to Finished on the VyOS 1.5 Circinus board.
a.apostoliuk moved T6130: [1.3.6->1.4.0-epa2 Migration] BGP "set community" missing from Open to Finished on the VyOS 1.4 Sagitta board.
a.apostoliuk closed T6130: [1.3.6->1.4.0-epa2 Migration] BGP "set community" missing, a subtask of T5938: Migration fail root task for 1.4-rc, as Resolved.
a.apostoliuk changed the status of T6130: [1.3.6->1.4.0-epa2 Migration] BGP "set community" missing, a subtask of T5938: Migration fail root task for 1.4-rc, from In progress to Needs testing.
a.apostoliuk changed the status of T6130: [1.3.6->1.4.0-epa2 Migration] BGP "set community" missing from In progress to Needs testing.
a.apostoliuk triaged T6157: Can not create two GRE tunnels to the same DST but from different SRC addresses as Normal priority.
Mar 21 2024
Mar 21 2024
a.apostoliuk triaged T6150: Impossible to set a static IP address via RADIUS in IPoE as Normal priority.
a.apostoliuk changed the status of T6150: Impossible to set a static IP address via RADIUS in IPoE from Open to In progress.
Mar 18 2024
Mar 18 2024
a.apostoliuk changed the status of T6130: [1.3.6->1.4.0-epa2 Migration] BGP "set community" missing, a subtask of T5938: Migration fail root task for 1.4-rc, from Open to In progress.