Bug 1915687 - [OVS IPsec] No ESP in packets through OVS tunnel with type=ip6gre
Summary: [OVS IPsec] No ESP in packets through OVS tunnel with type=ip6gre
Keywords:
Status: CLOSED NOTABUG
Alias: None
Product: Red Hat Enterprise Linux Fast Datapath
Classification: Red Hat
Component: openvswitch3.1
Version: FDP 21.A
Hardware: x86_64
OS: Linux
medium
medium
Target Milestone: ---
: ---
Assignee: Mike Pattrick
QA Contact: qding
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2021-01-13 08:53 UTC by qding
Modified: 2023-08-04 18:25 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2023-08-04 18:23:48 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
log for "journalctl -u ipsec" (115.20 KB, text/plain)
2021-01-15 09:51 UTC, qding
no flags Details
log for "journalctl -u openvswitch-ipsec" (3.63 KB, text/plain)
2021-01-15 09:52 UTC, qding
no flags Details


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FD-1019 0 None None None 2021-10-29 08:57:15 UTC

Description qding 2021-01-13 08:53:37 UTC
Description of problem:

OVS IPsec doesn't work for IPv6 tunnel.

Version-Release number of selected component (if applicable):

[root@dell-per730-04 ~]# rpm -qa | grep openvswitch
openvswitch2.13-ipsec-2.13.0-79.el8fdp.x86_64
openvswitch-selinux-extra-policy-1.0-24.el8fdp.noarch
openvswitch2.13-2.13.0-79.el8fdp.x86_64
python3-openvswitch2.13-2.13.0-79.el8fdp.x86_64


[root@dell-per730-04 ~]# ovs-vsctl show
5fa03d0e-dac3-483a-9e3d-1f43fb7a21f5
    Bridge ovsbr0
        Port ovsbr0
            Interface ovsbr0
                type: internal
        Port tun123
            Interface tun123
                type: ip6gre
                options: {local_ip="2001:db8::123:1", psk=test123, remote_ip="2001:db8::123:2"}
    ovs_version: "2.13.2"
[root@dell-per730-04 ~]# 
[root@dell-per730-04 ~]# 
[root@dell-per730-04 ~]# cat /etc/ipsec.conf 
# Generated by ovs-monitor-ipsec...do not modify by hand!


config setup
    uniqueids=yes

conn %default
    keyingtries=%forever
    type=transport
    auto=route
    ike=aes_gcm256-sha2_256
    esp=aes_gcm256
    ikev2=insist



How reproducible: always


Steps to Reproduce:
1. 
2.
3.

Actual results:
No ESP in packets through the tunnel


Expected results:
ESP is added in packets through the tunnel

Additional info:

Comment 1 Mark Gray 2021-01-14 13:54:13 UTC
Can you post any libreswan messages in the journal and the ovs-monitor-ipsec.log file?

Comment 2 qding 2021-01-15 09:51:59 UTC
Created attachment 1747724 [details]
log for "journalctl -u ipsec"

Comment 3 qding 2021-01-15 09:52:59 UTC
Created attachment 1747725 [details]
log for "journalctl -u openvswitch-ipsec"

Comment 5 Mark Gray 2021-01-15 13:25:41 UTC
Hi,

Tunnel type ip6gre is not supported. The only supported types are: gre, stt, vxlan, geneve

Mark

Comment 6 qding 2021-01-18 11:43:57 UTC
(In reply to Mark Gray from comment #5)
> Hi,
> 
> Tunnel type ip6gre is not supported. The only supported types are: gre, stt,
> vxlan, geneve
> 
> Mark

IPv6 vxlan and IPv6 geneve have no problem.
But we have been using ip6gre to create ipv6 GRE tunnel and I tried with type=gre and remote_ip/local_ip as IPv6 address but it doesn't work even without IPsec. Please make sure only support gre is expected.
I don't try with stt and don't know yet how to use it.

Thanks.

Comment 7 Mark Gray 2021-01-18 17:12:13 UTC
(In reply to qding from comment #6)
> (In reply to Mark Gray from comment #5)
> > Hi,
> > 
> > Tunnel type ip6gre is not supported. The only supported types are: gre, stt,
> > vxlan, geneve
> > 
> > Mark
> 
> IPv6 vxlan and IPv6 geneve have no problem.
> But we have been using ip6gre to create ipv6 GRE tunnel and I tried with
> type=gre and remote_ip/local_ip as IPv6 address but it doesn't work even
> without IPsec. Please make sure only support gre is expected.
> I don't try with stt and don't know yet how to use it.
> 
> Thanks.

Ok if IPv6 generally works (for vxlan and geneve), can we change the title of this bug to GRE IPv6 support?

Comment 8 qding 2021-01-19 00:58:53 UTC
(In reply to Mark Gray from comment #7)
> 
> Ok if IPv6 generally works (for vxlan and geneve), can we change the title
> of this bug to GRE IPv6 support?

I've changed it and please see if it's ok. Thanks.

Comment 9 Mark Gray 2021-01-19 15:18:09 UTC
Yes, looks fine now.

Comment 12 Mike Pattrick 2023-08-02 15:56:49 UTC
ovs-monitor-ipsec doesn't currently support ip6gre at all. I'll look into adding it.

Comment 13 Mike Pattrick 2023-08-02 20:00:26 UTC
I quickly added ip6gre to ovs-monitor-ipsec, but still wasn't able to establish a full ipsec tunnel.

From a quick debugging session I see IKE negotiate, and even "ip xfrm state" shows the proper configuration. But egress ipv6 gre packets aren't encrypted properly.

Comment 14 Flavio Leitner 2023-08-04 18:23:48 UTC
Thanks Mike. The IPSEC w/ IPv6 is not supported downstream.
I am closing this bug because we don't have RFE to enable that.
fbl


Note You need to log in before you can comment on or make changes to this bug.