Hi everyone,
I have an IPSEC established to a Sophos with VTI and OSPF, that I’ve being noticing some increase of packet loss over this VPN after installing 1.5-rolling-202401150027, right now the VTI interface is down and is not coming up, below the logs reporting the issue:
===================================================================
vyos@lab:~$ show ver
Version: VyOS 1.5-rolling-202401150027
Release train: current
Built by: [email protected]
Built on: Mon 15 Jan 2024 02:23 UTC
Build UUID: ae33bb51-d123-4610-a2cb-db17358ce55c
Build commit ID: 365f10340ec2f1
Architecture: x86_64
Boot via: installed image
System type: VMware guest
Hardware vendor: VMware, Inc.
Hardware model: VMware Virtual Platform
Hardware S/N: VMware-56 4d c7 62 3a b5 bb 1d-b9 5d 75 20 89 82 c2 63
Hardware UUID: 62c74d56-b53a-1dbb-b95d-75208982c263
Copyright: VyOS maintainers and contributors
vyos@lab:~$
===================================================================
Feb 20 03:09:31 lab kernel: [633314.314528] ll header: 00000000: 00 0c 29 82 c2 63 d4 76 a0 57 2e 10 08 00
Feb 20 03:09:31 lab charon: 15[NET] <165> received packet: from X.X.X.X[4500] to 192.168.1.13[4500] (496 bytes)
Feb 20 03:09:31 lab charon-systemd[3821]: received packet: from X.X.X.X[4500] to 192.168.1.13[4500] (496 bytes)
Feb 20 03:09:31 lab charon: 15[ENC] <165> parsed IKE_AUTH request 1 [ IDi IDr AUTH SA TSi TSr N(MULT_AUTH) N(EAP_ONLY) N(MSG_ID_SYN_SUP) ]
Feb 20 03:09:31 lab charon: 15[CFG] <165> looking for peer configs matching 192.168.1.13[X.X.X.com]...X.X.X.X[X.X.X.com]
Feb 20 03:09:31 lab charon-systemd[3821]: parsed IKE_AUTH request 1 [ IDi IDr AUTH SA TSi TSr N(MULT_AUTH) N(EAP_ONLY) N(MSG_ID_SYN_SUP) ]
Feb 20 03:09:31 lab charon-systemd[3821]: looking for peer configs matching 192.168.1.13[X.X.X.com]...X.X.X.X[X.X.X.com]
Feb 20 03:09:31 lab charon: 15[CFG] <SOPHOS_HOME1|165> selected peer config 'SOPHOS_HOME1'
Feb 20 03:09:31 lab charon-systemd[3821]: selected peer config 'SOPHOS_HOME1'
Feb 20 03:09:31 lab charon: 15[IKE] <SOPHOS_HOME1|165> authentication of 'X.X.X.com' with pre-shared key successful
Feb 20 03:09:31 lab charon-systemd[3821]: authentication of 'X.X.X.com' with pre-shared key successful
Feb 20 03:09:31 lab charon: 15[IKE] <SOPHOS_HOME1|165> authentication of 'X.X.X.com' (myself) with pre-shared key
Feb 20 03:09:31 lab charon-systemd[3821]: authentication of 'X.X.X.com' (myself) with pre-shared key
Feb 20 03:09:31 lab charon: 15[IKE] <SOPHOS_HOME1|165> IKE_SA SOPHOS_HOME1[165] established between 192.168.1.13[X.X.X.com]...X.X.X.X[X.X.X.com]
Feb 20 03:09:31 lab charon-systemd[3821]: IKE_SA SOPHOS_HOME1[165] established between 192.168.1.13[X.X.X.com]...X.X.X.X[X.X.X.com]
Feb 20 03:09:31 lab charon: 15[IKE] <SOPHOS_HOME1|165> scheduling rekeying in 12497s
Feb 20 03:09:31 lab charon-systemd[3821]: scheduling rekeying in 12497s
Feb 20 03:09:31 lab charon: 15[IKE] <SOPHOS_HOME1|165> maximum IKE_SA lifetime 13757s
Feb 20 03:09:31 lab charon-systemd[3821]: maximum IKE_SA lifetime 13757s
Feb 20 03:09:31 lab charon: 15[CFG] <SOPHOS_HOME1|165> selected proposal: ESP:AES_CBC_256/HMAC_SHA2_512_256/NO_EXT_SEQ
Feb 20 03:09:31 lab charon-systemd[3821]: selected proposal: ESP:AES_CBC_256/HMAC_SHA2_512_256/NO_EXT_SEQ
Feb 20 03:09:31 lab charon: 15[IKE] <SOPHOS_HOME1|165> CHILD_SA SOPHOS_HOME1-vti{366} established with SPIs cd697fbf_i c9cf32d6_o and TS 0.0.0.0/0 === 0.0.0.0/0
Feb 20 03:09:31 lab charon-systemd[3821]: CHILD_SA SOPHOS_HOME1-vti{366} established with SPIs cd697fbf_i c9cf32d6_o and TS 0.0.0.0/0 === 0.0.0.0/0
Feb 20 03:09:31 lab vti-up-down[214613]: Interface vti1 up-client SOPHOS_HOME1-vti
Feb 20 03:09:32 lab charon: 15[CHD] <SOPHOS_HOME1|165> updown: Error: FIB table does not exist.
Feb 20 03:09:32 lab charon-systemd[3821]: updown: Error: FIB table does not exist.
Feb 20 03:09:32 lab charon: 15[ENC] <SOPHOS_HOME1|165> generating IKE_AUTH response 1 [ IDr AUTH SA TSi TSr ]
Feb 20 03:09:32 lab charon-systemd[3821]: generating IKE_AUTH response 1 [ IDr AUTH SA TSi TSr ]
Feb 20 03:09:32 lab charon: 15[NET] <SOPHOS_HOME1|165> sending packet: from 192.168.1.13[4500] to X.X.X.X[4500] (272 bytes)
Feb 20 03:09:32 lab charon-systemd[3821]: sending packet: from 192.168.1.13[4500] to X.X.X.X[4500] (272 bytes)
Feb 20 03:09:32 lab charon: 13[NET] <SOPHOS_HOME1|165> received packet: from X.X.X.X[4500] to 192.168.1.13[4500] (672 bytes)
Feb 20 03:09:32 lab charon-systemd[3821]: received packet: from X.X.X.X[4500] to 192.168.1.13[4500] (672 bytes)
Feb 20 03:09:32 lab charon-systemd[3821]: parsed CREATE_CHILD_SA request 2 [ SA No KE TSi TSr ]
Feb 20 03:09:32 lab charon: 13[ENC] <SOPHOS_HOME1|165> parsed CREATE_CHILD_SA request 2 [ SA No KE TSi TSr ]
Feb 20 03:09:32 lab charon: 13[CFG] <SOPHOS_HOME1|165> selected proposal: ESP:AES_CBC_256/HMAC_SHA2_512_256/NO_EXT_SEQ
Feb 20 03:09:32 lab charon: 13[IKE] <SOPHOS_HOME1|165> ignoring KE exchange, agreed on a non-PFS proposal
Feb 20 03:09:32 lab charon-systemd[3821]: selected proposal: ESP:AES_CBC_256/HMAC_SHA2_512_256/NO_EXT_SEQ
Feb 20 03:09:32 lab charon-systemd[3821]: ignoring KE exchange, agreed on a non-PFS proposal
Feb 20 03:09:32 lab charon: 13[IKE] <SOPHOS_HOME1|165> CHILD_SA SOPHOS_HOME1-vti{367} established with SPIs c86b1eb6_i c8fa29b9_o and TS 0.0.0.0/0 === 0.0.0.0/0
Feb 20 03:09:32 lab charon-systemd[3821]: CHILD_SA SOPHOS_HOME1-vti{367} established with SPIs c86b1eb6_i c8fa29b9_o and TS 0.0.0.0/0 === 0.0.0.0/0
Feb 20 03:09:32 lab vti-up-down[214619]: Interface vti1 up-client SOPHOS_HOME1-vti
Feb 20 03:09:32 lab charon: 13[CHD] <SOPHOS_HOME1|165> updown: Error: FIB table does not exist.
Feb 20 03:09:32 lab charon-systemd[3821]: updown: Error: FIB table does not exist.
Feb 20 03:09:32 lab charon: 13[ENC] <SOPHOS_HOME1|165> generating CREATE_CHILD_SA response 2 [ SA No TSi TSr ]
Feb 20 03:09:32 lab charon: 13[NET] <SOPHOS_HOME1|165> sending packet: from 192.168.1.13[4500] to X.X.X.X[4500] (224 bytes)
Feb 20 03:09:32 lab charon-systemd[3821]: generating CREATE_CHILD_SA response 2 [ SA No TSi TSr ]
Feb 20 03:09:32 lab charon-systemd[3821]: sending packet: from 192.168.1.13[4500] to X.X.X.X[4500] (224 bytes)
Feb 20 03:09:33 lab charon: 07[IKE] <SOPHOS_HOME1|158> giving up after 5 retransmits
Feb 20 03:09:33 lab charon-systemd[3821]: giving up after 5 retransmits
Feb 20 03:09:33 lab vti-up-down[214624]: Interface vti1 down-client SOPHOS_HOME1-vti
Feb 20 03:09:33 lab zebra[1672]: [HSYZM-HV7HF] Extended Error: Nexthop device is not up
Feb 20 03:09:33 lab zebra[1672]: [WVJCK-PPMGD][EC 4043309093] netlink-dp (NS 0) error: Network is down, type=RTM_NEWNEXTHOP(104), seq=1413, pid=2740933800
Feb 20 03:09:33 lab zebra[1672]: [HSYZM-HV7HF] Extended Error: Nexthop id does not exist
Feb 20 03:09:33 lab zebra[1672]: [WVJCK-PPMGD][EC 4043309093] netlink-dp (NS 0) error: Invalid argument, type=RTM_NEWROUTE(24), seq=1414, pid=2740933800
Feb 20 03:09:33 lab zebra[1672]: [X5XE1-RS0SW][EC 4043309074] Failed to install Nexthop (278[if 10]) into the kernel
Feb 20 03:09:33 lab zebra[1672]: [VYKYC-709DP] default(0:254):192.168.232.4/30: Route install failed
Feb 20 03:09:33 lab vti-up-down[214629]: Interface vti1 down-client SOPHOS_HOME1-vti
Feb 20 03:09:34 lab systemd[1]: [email protected]: Deactivated successfully.
Feb 20 03:09:34 lab systemd[1]: [email protected]: Scheduled restart job, restart counter is at 61776.
Feb 20 03:09:34 lab systemd[1]: Stopped [email protected] - Serial Getty on ttyS0.
Feb 20 03:09:34 lab systemd[1]: Started [email protected] - Serial Getty on ttyS0.
Feb 20 03:09:34 lab agetty[214633]: /dev/ttyS0: not a tty
Feb 20 03:09:44 lab systemd[1]: [email protected]: Deactivated successfully.
Feb 20 03:09:44 lab kernel: [633327.744709] net_ratelimit: 78 callbacks suppressed
Feb 20 03:09:44 lab kernel: [633327.744744] IPv4: martian source 192.168.22.10 from 192.168.1.
===================================================================
10: vti1@NONE: <NOARP> mtu 1400 qdisc noqueue state DOWN group default qlen 1000
link/none
inet 192.168.232.6/30 brd 192.168.232.7 scope global vti1
valid_lft forever preferred_lft forever
===================================================================
vyos@lab:~$ sh vpn ipsec connections
Connection State Type Remote address Local TS Remote TS Local id Remote id Proposal
---------------- ------- ------ ----------------- ---------- ----------- --------------- ----------------- ---------------------------------------
SOPHOS_HOME1 up IKEv2 x.x.x.com - - x.x.x.com x.x.x.com AES_CBC/256/HMAC_SHA2_512_256/MODP_2048
SOPHOS_HOME1-vti up IPsec x.x.x.com 0.0.0.0/0 0.0.0.0/0 x.x.x.com x.x.x.com AES_CBC/256/HMAC_SHA2_512_256/None
::/0 ::/0
===================================================================