Page MenuHomeVyOS Platform

op-mode IPSec show vpn ike sa always shows L-TIME 0
Open, Requires assessmentPublicBUG

Description

IKE configuration:

set vpn ipsec ike-group IKE-GRP-VTI ikev2-reauth 'no'
set vpn ipsec ike-group IKE-GRP-VTI key-exchange 'ikev1'
set vpn ipsec ike-group IKE-GRP-VTI lifetime '3600'
set vpn ipsec ike-group IKE-GRP-VTI proposal 1 dh-group '2'
set vpn ipsec ike-group IKE-GRP-VTI proposal 1 encryption 'aes256'
set vpn ipsec ike-group IKE-GRP-VTI proposal 1 hash 'sha1'

Output

vyos@r1-roll:~$ show vpn ike sa
Peer ID / IP                            Local ID / IP               
------------                            -------------
192.0.2.1 192.0.2.1                     192.0.2.2 192.0.2.2                    

    State  IKEVer  Encrypt      Hash          D-H Group      NAT-T  A-Time  L-Time
    -----  ------  -------      ----          ---------      -----  ------  ------
    up     IKEv1   AES_CBC_256  HMAC_SHA1_96  MODP_1024      no     607     0

Expected L-TIME 3600

Details

Difficulty level
Easy (less than an hour)
Version
VyOS 1.4-rolling-202107280117
Why the issue appeared?
Will be filled on close
Is it a breaking change?
Perfectly compatible