apache / apache/cloudstack

Site to Site VPN Connections shows disconnected if there are no running vm's

Đang mở
#13,687 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
component:networking component:virtual-router component:vpc
Ngôn ngữ chính
Java
Star
3.1k
Fork
1.4k
Merge trung bình
6 ngày 19 giờ
Pull request đã merge (30 ngày)
32

Mô tả

### problem

Site to Site VPN Connections shows disconnected if there are no running vm's

### versions

ACS 4.22

### The steps to reproduce the bug

Steps to reproduce the issue

1. Create a 3 vpc networks

vpc1 > 172.30.21.0/24
vpc2 > 172.30.22.0/24

2. Create a respective network tier in each vpc

vpc1-tier1 > 172.30.21.0/28
vpc2-tier1 > 172.30.22.0/28

3. Enable VPN for each vpc

Navigate to each vpc source nat ip and enable vpn

vpc1 > publicip address (source nat) > Enable vpn
vpc2 > publicip address (source nat) > Enable vpn

4. Create Customer Gateway for each each vpc

Navigate > Network > VPN Customer Gateway

Name (vpc1-gateway) > Gateway ( publicip address (source nat) > CIDR list (172.30.21.0/28 ) > IPsec preshared-key ( from step 3 for each vpc)
Name (vpc2-gateway) > Gateway ( publicip address (source nat) > CIDR list (172.30.21.0/28 ) > IPsec preshared-key ( from step 3 for each vpc)

5. Enable VPN Gateway

Home > Network > VPC > VPC-1 > VPN gateway (Enable)
Home > Network > VPC > VPC-2 > VPN gateway (Enable)

6. Create a vpn connections to

VPC1 ↔ VPC2 ( VPC1 (active , VPC2 (passive)))

cmk createVpnConnection s2svpngatewayid= <> s2scustomergatewayid=<> passive=true

cmk createVpnConnection s2svpngatewayid= <> s2scustomergatewayid=<> passive=false

7. Check all the vpn connections > All are in disconnected state

Image

Workaorund

8. Deploy vm's in each vpc tier become vpn connections are connected

Only then the vpn connections are established

Image

Please check the following commands and logs to troubleshoot ipsec related issues

root@r-86-VM:~# ipsec statusall
root@r-86-VM:~# ip xfrm state
root@r-86-VM:~# ip xfrm policy

root@r-86-VM:/etc/ipsec.d#cat ipsec.vpn-.conf
root@r-86-VM:/etc/ipsec.d#cat ipsec.vpn-.secrets
root@r-86-VM:/etc/ipsec.d#cat l2tp.conf

root@r-86-VM:~#cat /var/log/daemon.log

### What to do about it?

The site to site vpn tunnel should get established even if there are no vm's present in the initial deployment

IKE/IPsec negotiation happens VR-to-VR over the public IPs that negotiation doesn't inherently need a guest VM to exist.

Currently, the IKE initiation on the active side is contingent on some triggering event , that trigger generally comes from a config re-push tied to VM deployment (which touches routing/network state across the VRs),

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Tái hiện thiết lập kết nối VPN mà không có VM nào đang chạy, sau đó so sánh với trạng thái sau khi triển khai các VM. Bắt đầu với các kết quả được liệt kê của ipsec statusall, ip xfrm state, ip xfrm policy, các tệp cấu hình và /var/log/daemon.log trên VM router. Được xem là hoàn tất khi đường hầm IKE/IPsec được thiết lập mà không cần các VM khách.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Lĩnh vực
networking
Loại issue
Lỗi
Độ khó
4/5
Thời gian dự kiến
3-5 ngày
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Khá rõ ràng
Mức phù hợp với người mới
48/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.