Activity log for bug #1726422

Date Who What changed Old value New value Message
2017-10-23 14:28:36 zhichao zhu bug added bug
2017-10-23 14:32:18 zhichao zhu description Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel. Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode. Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support,like ike_phase1_mode:["main",null]. Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel. Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode. Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support,like ike_phase1_mode:["main","aggressive",null]. add aggressive mode to solve bug/1701413
2017-10-23 23:10:51 zhichao zhu description Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel. Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode. Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support,like ike_phase1_mode:["main","aggressive",null]. add aggressive mode to solve bug/1701413 Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel. Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode. Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support. add aggressive mode to solve bug/1701413
2017-10-23 23:11:41 zhichao zhu description Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel. Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode. Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support. add aggressive mode to solve bug/1701413 Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel. Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode. Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support. and add aggressive mode to solve bug/1701413
2017-10-23 23:19:29 zhichao zhu description Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel. Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode. Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support. and add aggressive mode to solve bug/1701413 Ike version V1 divides two phases to create ike&ipsec tunnel,the ike_phase1_mode(main mode or aggresive mode) is used in first phase to negotiate ike tunnel. Ike version v2 create ipsec sa in only one phase. If ike policy uses ike V2,it will be unnecessary to use ike_phase1_mode. The ike policy is shown in the following,phase1_negotiation_mode should be None root@ubuntu:~# neutron vpn-ikepolicy-show c32c991d-ecb9-460e-b829-8ce61bc8aed6 neutron CLI is deprecated and will be removed in the future. Use openstack CLI instead. +-------------------------+--------------------------------------+ | Field | Value | +-------------------------+--------------------------------------+ | auth_algorithm | sha1 | | description | | | encryption_algorithm | aes-128 | | id | c32c991d-ecb9-460e-b829-8ce61bc8aed6 | | ike_version | v2 | | lifetime | {"units": "seconds", "value": 3600} | | name | ikepolicy_a-1-1 | | pfs | group5 | | phase1_negotiation_mode | main | | project_id | 899181367cc14f498f089c82c0087637 | | tenant_id | 899181367cc14f498f089c82c0087637 | +-------------------------+--------------------------------------+ Now the ike_phase1_mode only support main mode,it cannot be modified to set null,it need be extended to support.
2017-10-24 01:54:08 OpenStack Infra neutron: status New In Progress
2017-10-24 01:54:08 OpenStack Infra neutron: assignee zhichao zhu (rtmdk)
2019-12-04 08:58:32 Slawek Kaplonski neutron: status In Progress New
2019-12-04 08:58:32 Slawek Kaplonski neutron: assignee zhichao zhu (rtmdk)
2019-12-04 08:58:36 Slawek Kaplonski tags timeout-abandon
2020-05-13 06:07:13 Dongcan Ye neutron: assignee Dongcan Ye (hellochosen)