kiranchavala opened a new issue, #13687:
URL: https://github.com/apache/cloudstack/issues/13687

   ### problem
   
   Site to Site VPN Connections shows disconnected if there are no running vm's
   
   ### versions
   
   ACS 4.22
   
   ### The steps to reproduce the bug
   
   Steps to reproduce the issue 
   
   1. Create a 3 vpc networks 
   
   vpc1 > 172.30.21.0/24
   vpc2 > 172.30.22.0/24
   
   2. Create a respective network tier in each vpc 
   
   vpc1-tier1 > 172.30.21.0/28
   vpc2-tier1 > 172.30.22.0/28
   
   3. Enable VPN for each vpc
   
   Navigate to each vpc source nat ip and enable vpn 
   
   vpc1 > publicip address (source nat) > Enable vpn
   vpc2 > publicip address (source nat) > Enable vpn
   
   4. Create Customer Gateway for each each vpc
   
   Navigate > Network > VPN Customer Gateway
   
   Name (vpc1-gateway) > Gateway ( publicip address (source nat) > CIDR list 
(172.30.21.0/28 )  > IPsec preshared-key  ( from step 3 for each vpc)
   Name (vpc2-gateway) > Gateway ( publicip address (source nat) > CIDR list 
(172.30.21.0/28 )  > IPsec preshared-key  ( from step 3 for each vpc)
   
   5. Enable VPN Gateway 
   
   Home > Network > VPC > VPC-1 > VPN gateway (Enable)
   Home > Network > VPC > VPC-2 > VPN gateway (Enable)
   
   6. Create a vpn connections to 
   
   VPC1 ↔ VPC2 ( VPC1 (active , VPC2 (passive)))
   
   cmk createVpnConnection s2svpngatewayid= <> s2scustomergatewayid=<> 
passive=true
   
   cmk createVpnConnection s2svpngatewayid= <> s2scustomergatewayid=<> 
passive=false
   
   
   7. Check all the vpn connections  > All are in disconnected state 
   
   <img width="1147" height="262" alt="Image" 
src="https://github.com/user-attachments/assets/d50dc703-83fb-47c6-a252-c108c328ae74";
 />
   
   
   Workaorund 
   
   8. Deploy vm's in each vpc tier become vpn connections are connected 
   
   Only  then the vpn connections are established
   
   <img width="1612" height="224" alt="Image" 
src="https://github.com/user-attachments/assets/b89567cf-f3b8-46cb-8980-8cf57cb3d3b1";
 />
   
    
   
   Please check the following commands and logs  to troubleshoot ipsec related 
issues 
   
   root@r-86-VM:~# ipsec statusall
   root@r-86-VM:~# ip xfrm state
   root@r-86-VM:~# ip xfrm policy
   
   root@r-86-VM:/etc/ipsec.d#cat ipsec.vpn-<publicip>.conf
   root@r-86-VM:/etc/ipsec.d#cat ipsec.vpn-<publicip>.secrets
   root@r-86-VM:/etc/ipsec.d#cat l2tp.conf
   
   
   root@r-86-VM:~#cat /var/log/daemon.log
   
   
   ### What to do about it?
   
   The site to site vpn tunnel should get established even if there are no vm's 
present in the initial deployment 
   
   
   IKE/IPsec negotiation happens VR-to-VR over the public IPs that negotiation 
doesn't inherently need a guest VM to exist. 
   
   Currently, the IKE initiation on the active side is contingent on some 
triggering event , that trigger generally comes  from a config re-push tied to 
VM deployment (which touches routing/network state across the VRs),


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to