kiranchavala opened a new issue, #13687: URL: https://github.com/apache/cloudstack/issues/13687
### problem Site to Site VPN Connections shows disconnected if there are no running vm's ### versions ACS 4.22 ### The steps to reproduce the bug Steps to reproduce the issue 1. Create a 3 vpc networks vpc1 > 172.30.21.0/24 vpc2 > 172.30.22.0/24 2. Create a respective network tier in each vpc vpc1-tier1 > 172.30.21.0/28 vpc2-tier1 > 172.30.22.0/28 3. Enable VPN for each vpc Navigate to each vpc source nat ip and enable vpn vpc1 > publicip address (source nat) > Enable vpn vpc2 > publicip address (source nat) > Enable vpn 4. Create Customer Gateway for each each vpc Navigate > Network > VPN Customer Gateway Name (vpc1-gateway) > Gateway ( publicip address (source nat) > CIDR list (172.30.21.0/28 ) > IPsec preshared-key ( from step 3 for each vpc) Name (vpc2-gateway) > Gateway ( publicip address (source nat) > CIDR list (172.30.21.0/28 ) > IPsec preshared-key ( from step 3 for each vpc) 5. Enable VPN Gateway Home > Network > VPC > VPC-1 > VPN gateway (Enable) Home > Network > VPC > VPC-2 > VPN gateway (Enable) 6. Create a vpn connections to VPC1 ↔ VPC2 ( VPC1 (active , VPC2 (passive))) cmk createVpnConnection s2svpngatewayid= <> s2scustomergatewayid=<> passive=true cmk createVpnConnection s2svpngatewayid= <> s2scustomergatewayid=<> passive=false 7. Check all the vpn connections > All are in disconnected state <img width="1147" height="262" alt="Image" src="https://github.com/user-attachments/assets/d50dc703-83fb-47c6-a252-c108c328ae74" /> Workaorund 8. Deploy vm's in each vpc tier become vpn connections are connected Only then the vpn connections are established <img width="1612" height="224" alt="Image" src="https://github.com/user-attachments/assets/b89567cf-f3b8-46cb-8980-8cf57cb3d3b1" /> Please check the following commands and logs to troubleshoot ipsec related issues root@r-86-VM:~# ipsec statusall root@r-86-VM:~# ip xfrm state root@r-86-VM:~# ip xfrm policy root@r-86-VM:/etc/ipsec.d#cat ipsec.vpn-<publicip>.conf root@r-86-VM:/etc/ipsec.d#cat ipsec.vpn-<publicip>.secrets root@r-86-VM:/etc/ipsec.d#cat l2tp.conf root@r-86-VM:~#cat /var/log/daemon.log ### What to do about it? The site to site vpn tunnel should get established even if there are no vm's present in the initial deployment IKE/IPsec negotiation happens VR-to-VR over the public IPs that negotiation doesn't inherently need a guest VM to exist. Currently, the IKE initiation on the active side is contingent on some triggering event , that trigger generally comes from a config re-push tied to VM deployment (which touches routing/network state across the VRs), -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
