VPNaaS: leftid should be configurable

Bug #1513353 reported by Yi Jing Zhu
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
neutron
Won't Fix
Low
Yi Jing Zhu

Bug Description

Currently, both left & leftid are filled with external_ip automatically. But sometimes, user may want to specify the leftid as they desired, such as an email address.
It would be better if this can be supported.

Pre-conditions: None

Step-by-step reproduction steps:
1) create an ipsec connection from dashboard or CLI, there is no leftid option.

Version:
Stable Kilo/CentOS7/RDO

Thanks!

Tags: vpnaas
Yi Jing Zhu (nick-zhuyj)
summary: - leftid should be configurable
+ vpnaas - leftid should be configurable
summary: - vpnaas - leftid should be configurable
+ VPNaaS: leftid should be configurable
Kyle Mestery (mestery)
Changed in neutron:
status: New → Triaged
importance: Undecided → Low
Revision history for this message
Paul Michali (pcm) wrote :

Are there requests from users for this capability? We have the ability to use email address for peer, but I've never seen it used.

Revision history for this message
Yi Jing Zhu (nick-zhuyj) wrote :

Hello Paul,
Our scenario is that, VPNaaS is behind a NAT, and then the leftid will be automatically filled as the local private IP of the neutron router gateway interface. But we don't want to expose this private IP for customers. So we want to fill the leftid as we desired.

Thanks!

Changed in neutron:
assignee: nobody → Chirag Shahani (chirag-shahani)
Changed in neutron:
assignee: Chirag Shahani (chirag-shahani) → Yi Jing Zhu (nick-zhuyj)
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to neutron-vpnaas (master)

Reviewed: https://review.openstack.org/310676
Committed: https://git.openstack.org/cgit/openstack/neutron-vpnaas/commit/?id=7cf4ef682f83fc08484011454f62c27882064dff
Submitter: Jenkins
Branch: master

commit 7cf4ef682f83fc08484011454f62c27882064dff
Author: nick.zhuyj <email address hidden>
Date: Wed Apr 27 03:36:02 2016 -0500

    Support local_id configuration

    In some case, we want to specify the local id instead of use the
    external ip. For example, the router is behind NAT, and we don't
    want to expose this IP to peer. This patch will make local_id
    configurable. Most often, local id would be domain name, email
    address etc. But if local id is not configured then external ip
    will still be used as the leftid.

    Note: this change is DocImpact & APIImpact

    Change-Id: I2433d72ba22ce410cbfafb7b8bfb16f51eefdfc1
    Closes-Bug: #1513353

Changed in neutron:
status: In Progress → Fix Released
Revision history for this message
Armando Migliaccio (armando-migliaccio) wrote :

The fix proposed here left much to be desired. A release note is missing, and the API extension was changed in place without taking into account that a user is unable to discover whether or not a system does support this capability. This should be reopened.

Changed in neutron:
status: Fix Released → In Progress
milestone: none → newton-1
Revision history for this message
Doug Hellmann (doug-hellmann) wrote : Fix included in openstack/neutron-vpnaas 9.0.0.0b1

This issue was fixed in the openstack/neutron-vpnaas 9.0.0.0b1 development milestone.

Changed in neutron:
milestone: newton-1 → newton-2
Changed in neutron:
milestone: newton-2 → newton-3
Changed in neutron:
milestone: newton-3 → newton-rc1
Changed in neutron:
milestone: newton-rc1 → ocata-1
Changed in neutron:
milestone: ocata-1 → ocata-2
Changed in neutron:
milestone: ocata-2 → ocata-3
Changed in neutron:
milestone: ocata-3 → ocata-rc1
Revision history for this message
Ihar Hrachyshka (ihar-hrachyshka) wrote :

Hm. Why do we track the bug for Neutron RC1? VPNaaS is not even in Stadium.

Changed in neutron:
milestone: ocata-rc1 → none
Revision history for this message
Cao Xuan Hoang (hoangcx) wrote :

I think this bug can be closed as it is covered by https://bugs.launchpad.net/neutron/+bug/1576888 and https://review.openstack.org/#/c/378068/ . Is that right?

Revision history for this message
Rodolfo Alonso (rodolfo-alonso-hernandez) wrote :

Bug closed due to lack of activity, please feel free to reopen if needed.

Changed in neutron:
status: In Progress → Won't Fix
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.