Not reproducible
VyOS 1.3.2-20230412083020
VyOS 1.3-stable-202304260442
Is it some specific image with custom packages?
I see correct routes after reboot
vyos@r1:~$ show ip route
Codes: K - kernel route, C - connected, S - static, R - RIP,
O - OSPF, I - IS-IS, B - BGP, E - EIGRP, N - NHRP,
T - Table, v - VNC, V - VNC-Direct, A - Babel, D - SHARP,
F - PBR, f - OpenFabric,
> - selected route, * - FIB route, q - queued, r - rejected, b - backup
S>* 0.0.0.0/0 [1/0] via 192.168.122.1, eth0, weight 1, 00:02:18
C>* 192.0.2.25/32 is directly connected, dum0, 00:02:19
C>* 192.168.122.0/24 is directly connected, eth0, 00:02:19
vyos@r1:~$
Try another image, or provide a complete configuration “show conf com”
Also, could you provide logs after reboot? sudo journalctl -b | tee
show conf com
set interfaces ethernet eth0 address '10.0.0.253/24'
set interfaces ethernet eth0 description 'wan'
set interfaces ethernet eth0 hw-id '00:15:5d:01:b6:1d'
set interfaces ethernet eth0 offload gro
set interfaces ethernet eth0 offload gso
set interfaces ethernet eth0 offload sg
set interfaces ethernet eth0 offload tso
set interfaces loopback lo
set nat source rule 10 destination address '10.1.0.0/24'
set nat source rule 10 exclude
set nat source rule 10 outbound-interface 'eth0'
set nat source rule 10 source address '10.0.0.0/24'
set protocols static route 0.0.0.0/0 next-hop 10.0.0.1
set service ssh port '22'
set system config-management commit-revisions '100'
set system console device ttyS0 speed '115200'
set system domain-name '<REDACTED>'
set system host-name 'vyos2'
set system login user vyos authentication encrypted-password '<REDACTED>'
set system login user vyos authentication plaintext-password ''
set system name-server '10.0.0.1'
set system ntp server time1.vyos.net
set system ntp server time2.vyos.net
set system ntp server time3.vyos.net
set system syslog global facility all level 'info'
set system syslog global facility protocols level 'debug'
set system time-zone 'America/New_York'
set vpn ipsec esp-group ESP-AZURE compression 'disable'
set vpn ipsec esp-group ESP-AZURE lifetime '3600'
set vpn ipsec esp-group ESP-AZURE mode 'tunnel'
set vpn ipsec esp-group ESP-AZURE pfs 'dh-group2'
set vpn ipsec esp-group ESP-AZURE proposal 1 encryption 'aes256'
set vpn ipsec esp-group ESP-AZURE proposal 1 hash 'sha1'
set vpn ipsec ike-group IKE-AZURE close-action 'none'
set vpn ipsec ike-group IKE-AZURE dead-peer-detection action 'restart'
set vpn ipsec ike-group IKE-AZURE dead-peer-detection interval '15'
set vpn ipsec ike-group IKE-AZURE dead-peer-detection timeout '30'
set vpn ipsec ike-group IKE-AZURE ikev2-reauth 'yes'
set vpn ipsec ike-group IKE-AZURE key-exchange 'ikev2'
set vpn ipsec ike-group IKE-AZURE lifetime '28800'
set vpn ipsec ike-group IKE-AZURE proposal 1 dh-group '2'
set vpn ipsec ike-group IKE-AZURE proposal 1 encryption 'aes256'
set vpn ipsec ike-group IKE-AZURE proposal 1 hash 'sha1'
set vpn ipsec ipsec-interfaces interface 'eth0'
set vpn ipsec site-to-site peer 40.85.167.160 authentication mode 'pre-shared-secret'
set vpn ipsec site-to-site peer 40.85.167.160 authentication pre-shared-secret '<REDACTED>'
set vpn ipsec site-to-site peer 40.85.167.160 connection-type 'respond'
set vpn ipsec site-to-site peer 40.85.167.160 default-esp-group 'ESP-AZURE'
set vpn ipsec site-to-site peer 40.85.167.160 ike-group 'IKE-AZURE'
set vpn ipsec site-to-site peer 40.85.167.160 ikev2-reauth 'inherit'
set vpn ipsec site-to-site peer 40.85.167.160 local-address '10.0.0.253'
set vpn ipsec site-to-site peer 40.85.167.160 tunnel 1 allow-nat-networks 'disable'
set vpn ipsec site-to-site peer 40.85.167.160 tunnel 1 allow-public-networks 'disable'
set vpn ipsec site-to-site peer 40.85.167.160 tunnel 1 local prefix '10.0.0.0/16'
set vpn ipsec site-to-site peer 40.85.167.160 tunnel 1 remote prefix '10.1.0.0/16'
I did rebuild from the rolling version of 1.3 and it is now working. By the way, I was able to recreate the issue using the docker container for 1.3 so there must have been a change somewhere that fixed it.
Thank you very much @Viacheslav and @kyle I appreciate the help.