Page MenuHomeVyOS Platform

Add support for cisco style GRE keepalives
Needs testing, Requires assessmentPublic

Description

Add Cisco style GRE keepalive support [0] using [1].

This is useful for tunnel up/down detection and is required by several DDoS mitigation providers.

[0] https://www.cisco.com/c/en/us/support/docs/ip/generic-routing-encapsulation-gre/118370-technote-gre-00.html
[1] https://github.com/Jamesits/linux-gre-keepalive

Details

Difficulty level
Unknown (require assessment)
Version
1.3-rolling-202101071430
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Perfectly compatible

Event Timeline

afics created this object in space S1 VyOS Public.

Why not use the mentioned method of sysctl`

VyOS 1.3: set system sysctl custom net.ipv4.conf.all.accept_local value 1
VyOS 1.4: set system sysctl parameter net.ipv4.conf.all.accept_local value 1

Or even limit this to your tunnel interface (tun10):

VyOS 1.3: set system sysctl custom net.ipv4.conf.tun10.accept_local value 1
VyOS 1.4: set system sysctl parameter net.ipv4.conf.tun10.accept_local value 1

It probably would make sense to add a real CLI note for this unter the tunnel interface.

c-po changed the task status from Open to Needs testing.Jun 4 2021, 12:51 PM
c-po claimed this task.
c-po moved this task from Need Triage to Backlog on the VyOS 1.3 Equuleus board.
c-po moved this task from Need Triage to Backlog on the VyOS 1.4 Sagitta board.

See [1] from the previous post:

Note: If you don't want to install anything and don't care about some potential security problems, just enable the following 2 options to get native GRE keepalive support on Linux: […]

I care. Setting these sysctl parameters allows for relaying arbitrary traffic through the router.