I have a iked(8) based VPN concentrator that terminates roadwarrior
connections from macOS and iOS devices.  It connects back to my
broader infrastructure via a static flow with GRE running on top.
Starting with 6.9 I noticed that bringing up a roadwarrior tunnel would
drop the network completely (pings to the public IP die).  I originally
thought it was related to
https://marc.info/?l=openbsd-misc&m=162212479408239&w=2
so I rolled back to 6.8 and waited for 7.0.  I upgraded to 7.0 and it seems
that the behavior remains.  I just finsihed reverting back to 6.8 to verify
that things work as expected and they do.

The roadwarrior is an automatic connection triggered by leaving a trusted
WiFi network, I asked iked to log verbose this morning and left the house
at 08:34.  You can see the connection in the log.  Around 09:10 I rebooted
to bsd.rd to re-install 6.8.  Links to iked.conf and the daemon log are
below.  I'm happy to upgrade to 7.0 again to debug this, but I don't really
know where to start.

--Matt

/var/log/daemon: https://www.going-flying.com/~mernisse/iked-7.0/daemon.txt
/etc/iked.conf: https://www.going-flying.com/~mernisse/iked-7.0/iked.conf.txt

Reply via email to