Page MenuHomePhabricator

VPN configuration error: IPv6 over IPv4 IPsec is not supported when using IPv6 ONLY tunnel.
Open, LowPublicBUG

Description

a similar problem is shown in the below link from ubnt edgeos . it seems this bug has carried over from the vyatta code.

problem shows up in both 1.1.x and 1.2.0 versions of vyos.
unable to use ipsec over ipv6

Derived from above link, when an ipv6 ipsec site to site vpn is created with a IPv6 VPN endpoint.

vpn {
     ipsec {
         auto-firewall-nat-exclude disable
         esp-group ESP1 {
             compression disable
             lifetime 3600
             mode transport
             pfs enable
             proposal 1 {
                 encryption aes128
                 hash sha1
             }
         }
         ike-group IKE1 {
             dead-peer-detection {
                 action restart
                 interval 15
                 timeout 90
             }
             ikev2-reauth no
             key-exchange ikev1
             lifetime 28800
             proposal 1 {
                 dh-group 2
                 encryption aes128
                 hash sha1
             }
         }
         ipsec-interfaces {
             interface eth0
         }
         site-to-site {
            peer yyyy:yyyy:yyyy:yyyy:yyyy:yyyy:yyyy:yyyy {
                authentication {
                    mode pre-shared-secret
                    pre-shared-secret PassWord
                }
                default-esp-group ESP1
                ike-group IKE1
                local-address xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx
                tunnel 1 {
                }
            }
         }
     }
 }

the following error appears:

commit
[ vpn ]
[ vpn ipsec site-to-site peer yyyy:yyyy:yyyy:yyyy:yyyy:yyyy:yyyy:yyyy tunnel 1 ]
VPN configuration error: IPv4 over IPv6 IPsec is not supported

Details

Difficulty level
Easy (less than an hour)
Version
1.2.0
Why the issue appeared?
Issues in third-party code

Event Timeline

masterit created this task.Oct 1 2017, 5:13 AM
masterit renamed this task from VPN configuration error: IPv6 over IPv4 IPsec is not supported even when using ipv6 only tunnel. to VPN configuration error: IPv6 over IPv4 IPsec is not supported when using IPv6 ONLY tunnel..Oct 3 2017, 2:05 AM
masterit updated the task description. (Show Details)
masterit changed Why the issue appeared? from Will be filled on close to Issues in third-party code.
syncer triaged this task as Low priority.Dec 21 2017, 9:47 PM
syncer edited projects, added VyOS 1.3 Equuleus; removed VyOS 2.0.x.
pasik added a subscriber: pasik.Oct 1 2018, 9:53 AM