StrongSwan ipsec.conf template is incomplete

Bug #1456336 reported by Tobias
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
neutron
Fix Released
Undecided
Yi Jing Zhu

Bug Description

After switching from openswan to strongswan our VPN services were not working anymore.

I figured out that the strongswan ipsec.conf template is incomplete. Attributes like IKE and IPSEC Policy were missing.

After modification of the template everything is working again. I attached my fixed template. Comments do not work for strongswan, so the template has no comments. Sorry for that.

Tags: vpnaas
Revision history for this message
Tobias (tobik) wrote :
Revision history for this message
Tobias (tobik) wrote :

Had to add "rightallowany=yes" to the template as dynamic ipsec site to site connections did not come up after ip change of the peer anymore.

Revision history for this message
Yi Jing Zhu (nick-zhuyj) wrote :

I met the same issue.

Changed in neutron:
assignee: nobody → Yi Jing Zhu (nick-zhuyj)
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix proposed to neutron-vpnaas (master)

Fix proposed to branch: master
Review: https://review.openstack.org/309372

Changed in neutron:
status: New → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to neutron-vpnaas (master)

Reviewed: https://review.openstack.org/309372
Committed: https://git.openstack.org/cgit/openstack/neutron-vpnaas/commit/?id=e10adef0b1a74e1df39d7d5c79257b9d5b9116b7
Submitter: Jenkins
Branch: master

commit e10adef0b1a74e1df39d7d5c79257b9d5b9116b7
Author: nick.zhuyj <email address hidden>
Date: Fri Apr 22 04:33:55 2016 -0500

    Strongswan: complete the ipsec.conf

    Many fields in strongswan ipsec.conf template is not specified.
    Thus they are used the default value instead of the value user
    provided. This patch fill those fields in the template.

    Change-Id: Ibc22db5d75eec6c9508880720dac6acd6197da22
    Closes-Bug: #1456336

Changed in neutron:
status: In Progress → Fix Released
Revision history for this message
Doug Hellmann (doug-hellmann) wrote : Fix included in openstack/neutron-vpnaas 9.0.0.0b1

This issue was fixed in the openstack/neutron-vpnaas 9.0.0.0b1 development milestone.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.