Page MenuHomeVyOS Platform

Rewrite vpn ipsec OP commands in new style XML syntax
Closed, ResolvedPublicFEATURE REQUEST


Migrate all vpn IPSec OP commands to VICI python module. We have already command show vpn ipsec sa which utilized VICI and will be good migrate others command to python code.


Difficulty level
Hard (possibly days)
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Perfectly compatible

Event Timeline

Going to mention this in here:

I had problem resetting a tunnel configured with ipsec sourced from loopback with gre on top of that. When configured with @remote_it I was unable to use reset command.

[email protected]_1.2.3:~$ reset vpn ipsec-peer @remote_id
Resetting tunnel 1 with peer @remote_id...
[email protected]_1.2.3:~$ show vpn ipsec sa | grep remote_id
peer-remote_id-tunnel-1     up       50 minutes  4M/2M

Only restart vpn actually reset that vpn peer (along with the rest of the tunnels configured on that vyosrouter)

And T2639 if it is relevant.

Viacheslav changed Difficulty level from Unknown (require assessment) to Hard (possibly days).
Viacheslav changed Is it a breaking change? from Unspecified (possibly destroys the router) to Perfectly compatible.
c-po reassigned this task from Dmitry to sdev.
c-po edited projects, added VyOS 1.4 Sagitta; removed VyOS 1.3 Equuleus.