Bug 1564529 - Auto DNS injects nonsense name servers after upgrade FC27-->FC28
Summary: Auto DNS injects nonsense name servers after upgrade FC27-->FC28
Keywords:
Status: CLOSED DUPLICATE of bug 1574939
Alias: None
Product: Fedora
Classification: Fedora
Component: NetworkManager-strongswan
Version: 28
Hardware: x86_64
OS: Linux
unspecified
high
Target Milestone: ---
Assignee: Pavel Šimerda
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-04-06 14:29 UTC by Mirek Svoboda
Modified: 2018-05-25 07:16 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-05-25 07:16:20 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)
journal (11.34 KB, text/x-vhdl)
2018-04-06 14:29 UTC, Mirek Svoboda
no flags Details
screenshot of relevant settings (62.67 KB, image/png)
2018-04-06 14:30 UTC, Mirek Svoboda
no flags Details
correct screenshot of related settings (64.71 KB, image/png)
2018-04-06 14:39 UTC, Mirek Svoboda
no flags Details

Description Mirek Svoboda 2018-04-06 14:29:59 UTC
Created attachment 1418186 [details]
journal

Description of problem:
After upgrade from FC27 to FC28 beta the name resolution stopped working while connected via IPsec VPN. The issue happens when DNS Automatic switch is on, see the attached screenshot. 

Server config did not change and connection towards it worked while using FC27 as a VPN road warrior. Relevant line from server config /etc/strongswan/ipsec.conf is:
rightdns=10.20.30.2,8.8.4.4,8.8.8.8

/etc/resolv.conf is populated with nonsense values as a result of establishing a VPN connection.

Version-Release number of selected component (if applicable):
NetworkManager-strongswan-1.4.3-1.fc28.x86_64
strongswan-charon-nm-5.6.2-2.fc28.x86_64
NetworkManager-strongswan-gnome-1.4.3-1.fc28.x86_64
strongswan-5.6.2-2.fc28.x86_64
gnome-shell-3.28.0-1.fc28.x86_64

How reproducible:

Steps to Reproduce:
1. Let use IPsec strongswan VPN server with DNS servers configured to be provided to the client. E.g. relevant line from server config /etc/strongswan/ipsec.conf is:
rightdns=10.20.30.2,8.8.4.4,8.8.8.8

2. Establish IPsec VPN connection from FC28 to the server, type IPsec/IKEv2 (strongswan), using Gnome GUI.

3. Nonsense values are added to /etc/resolv.conf


Actual results:
Nonsense values are added to /etc/resolv.conf
cat /etc/resolv.conf
# Generated by NetworkManager
nameserver 160.96.1.172
nameserver 64.96.1.172
nameserver 96.176.1.172
# NOTE: the libc resolver may not support more than 3 nameservers.
# The nameservers listed below may not be recognized.
nameserver 192.168.100.1


Expected results:
/etc/resolv.conf is populated with values provided by VPN server, i.e.
nameserver 8.8.8.8
nameserver 8.8.4.4
nameserver 10.20.30.2

Additional info:
See relevant excerpt from system journal attached.

Comment 1 Mirek Svoboda 2018-04-06 14:30:55 UTC
Created attachment 1418187 [details]
screenshot of relevant settings

Comment 2 Mirek Svoboda 2018-04-06 14:32:15 UTC
Workaround is to switch off the Automatic DNS setting and enter an DNS server(s) manually in the VPN connection config on the FC28 client.

Comment 3 Mirek Svoboda 2018-04-06 14:39:43 UTC
Created attachment 1418194 [details]
correct screenshot of related settings

Comment 4 Mikhail Zabaluev 2018-05-22 13:06:55 UTC
The root cause is likely bug 1574939.

Comment 5 Mirek Svoboda 2018-05-25 07:15:56 UTC
Duplicate of 1574939.

Comment 6 Mirek Svoboda 2018-05-25 07:16:20 UTC

*** This bug has been marked as a duplicate of bug 1574939 ***


Note You need to log in before you can comment on or make changes to this bug.