-
Bug
-
Resolution: Unresolved
-
Normal
-
None
-
rhel-10.0
-
No
-
Moderate
-
1
-
rhel-net-mgmt
-
ssg_networking
-
None
-
False
-
False
-
-
None
-
NMT SST - Refine next
-
-
None
-
None
-
Unspecified
-
Unspecified
-
Unspecified
-
None
What were you trying to do that didn't work?
Cannot setup ipsec 6in4 subnet tunnel via nmstatectl.
RHEL 10 works well if using ipsec.conf directly
conn hosta
ikev2=insist
left=2001:db8:d::a
leftid=@hosta.example.org
leftcert=hosta.example.org
leftsubnet=192.0.6.0/24
leftmodecfgclient=false
right=2001:db8:d::b
rightid=@hostb.example.org
rightsubnet=192.0.5.0/24
What is the impact of this issue to you?
Regression
Please provide the package NVR for which the bug is seen:
How reproducible is this bug?:
100%
Steps to reproduce
echo "
---
interfaces:
- name: hosta_conn
type: ipsec
ipv4:
enabled: true
dhcp: true
libreswan:
ikev2: insist
left: 2001:db8:d::a
leftid: '@hosta.example.org'
leftcert: hosta.example.org
leftsubnet: 192.0.6.0/24
leftmodecfgclient: false
right: 2001:db8:d::b
rightid: '@hostb.example.org'
rightsubnet: 192.0.5.0/24" | sudo nmstatectl apply -
Expected results
`ip x p` indicate 6in4 ipsec tunnel been created
Actual results
src 192.0.6.0/24 dst 192.0.5.0/24
dir out priority 1757393 ptype main
tmpl src 2001:db8:d::a dst 2001:db8:d::b
proto esp reqid 16389 mode tunnel
src 192.0.5.0/24 dst 192.0.6.0/24
dir fwd priority 1757393 ptype main
tmpl src 2001:db8:d::b dst 2001:db8:d::a
proto esp reqid 16389 mode tunnel
src 192.0.5.0/24 dst 192.0.6.0/24
dir in priority 1757393 ptype main
tmpl src 2001:db8:d::b dst 2001:db8:d::a
proto esp reqid 16389 mode tunnel