summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorNataliia Solomko <natalirs1985@gmail.com>2026-09-17 16:25:14 +0300
committerNataliia Solomko <natalirs1985@gmail.com>2026-09-17 17:50:20 +0300
commit5fbfd47c8a43d1836d064226f0ffb8ec91406cce (patch)
treec3afcb0d2a40947a262b2206b3e47c96359450b3
parentc91d7eb13252306629243d9699c92e38a5a12a71 (diff)
downloadvyos-1x-5fbfd47c8a43d1836d064226f0ffb8ec91406cce.tar.gz
vyos-1x-5fbfd47c8a43d1836d064226f0ffb8ec91406cce.zip
ipsec: T9320: Add deprecation warning for IKEv1 key-exchange
-rwxr-xr-xsmoketest/scripts/cli/test_vpn_ipsec.py15
-rwxr-xr-xsrc/conf_mode/vpn_ipsec.py43
2 files changed, 55 insertions, 3 deletions
diff --git a/smoketest/scripts/cli/test_vpn_ipsec.py b/smoketest/scripts/cli/test_vpn_ipsec.py
index 314287df4..744486022 100755
--- a/smoketest/scripts/cli/test_vpn_ipsec.py
+++ b/smoketest/scripts/cli/test_vpn_ipsec.py
@@ -946,7 +946,11 @@ class TestVPNIPsec(VyOSUnitTestSHIM.TestCase):
# Passing the 'unique = never' for StrongSwan's `connections.<conn>.unique` parameter
self.cli_set(base_path + ['disable-uniqreqids'])
- self.cli_commit()
+ # T9320: an explicit IKEv1 key-exchange must raise a deprecation warning
+ out = self.cli_commit()
+ self.assertIn(
+ f'DEPRECATION WARNING: IKE group "{ike_group}" uses deprecated IKEv1', out
+ )
swanctl_conf = read_file(swanctl_file)
self.assertConfigLine(swanctl_conf, 'proposals = aes256-sha1-prfsha1-modp1024')
@@ -995,7 +999,14 @@ class TestVPNIPsec(VyOSUnitTestSHIM.TestCase):
self.cli_set(peer_base_path + ['vti', 'bind', vti])
self.cli_set(peer_base_path + ['vti', 'esp-group', esp_group])
- self.cli_commit()
+ # T9320: an in-use IKE group without a key-exchange still accepts
+ # incoming IKEv1 and must raise a deprecation warning
+ out = self.cli_commit()
+ self.assertIn(
+ f'DEPRECATION WARNING: IKE group "{ike_group}" has no key-exchange set\n'
+ 'and will still accept incoming deprecated IKEv1 connections.',
+ out,
+ )
swanctl_conf = read_file(swanctl_file)
tmp = peer_ip.replace('.', '-')
diff --git a/src/conf_mode/vpn_ipsec.py b/src/conf_mode/vpn_ipsec.py
index be8eeca13..24220c435 100755
--- a/src/conf_mode/vpn_ipsec.py
+++ b/src/conf_mode/vpn_ipsec.py
@@ -25,6 +25,7 @@ from ipaddress import ip_address
from netaddr import IPNetwork
from netaddr import IPRange
+from vyos.base import DeprecationWarning
from vyos.config import Config
from vyos.config import config_dict_merge
from vyos.configdep import set_dependents
@@ -298,7 +299,47 @@ def verify(ipsec):
# need to use a pseudo-random function (PRF) with an authenticated encryption algorithm.
# If a hash algorithm is defined then it will be mapped to an equivalent PRF
if 'ike_group' in ipsec:
- for _, ike_config in ipsec['ike_group'].items():
+ # T9320: IKEv1 is deprecated and will be removed in a future StrongSwan
+ # release. Collect the IKE groups actually bound to a connection so we
+ # can also warn about groups without an explicit key-exchange: those
+ # propose IKEv2 when initiating but still accept IKEv1 when acting as a
+ # responder.
+ used_ike_groups = set()
+
+ l2tp_ike_group = dict_search('l2tp.ike_group', ipsec)
+ if l2tp_ike_group:
+ used_ike_groups.add(l2tp_ike_group)
+
+ for profile_conf in (ipsec.get('profile') or {}).values():
+ if 'ike_group' in profile_conf:
+ used_ike_groups.add(profile_conf['ike_group'])
+
+ for ra_conf in (dict_search('remote_access.connection', ipsec) or {}).values():
+ if 'ike_group' in ra_conf:
+ used_ike_groups.add(ra_conf['ike_group'])
+
+ for peer_conf in (dict_search('site_to_site.peer', ipsec) or {}).values():
+ if 'ike_group' in peer_conf:
+ used_ike_groups.add(peer_conf['ike_group'])
+
+ for ike_name, ike_config in ipsec['ike_group'].items():
+ # T9320: warn about the upcoming IKEv1 removal in StrongSwan.
+ key_exchange = ike_config.get('key_exchange')
+ if key_exchange == 'ikev1':
+ # Explicit IKEv1: the connection will stop working once
+ # StrongSwan removes IKEv1 support.
+ DeprecationWarning(
+ f'IKE group "{ike_name}" uses deprecated IKEv1, which will be '
+ 'removed in the future. Please migrate this configuration to IKEv2.'
+ )
+ elif key_exchange is None and ike_name in used_ike_groups:
+ # T9320: without an explicit key-exchange the group still
+ # accepts incoming IKEv1 connections when acting as a responder.
+ DeprecationWarning(
+ f'IKE group "{ike_name}" has no key-exchange set and will still '
+ 'accept incoming deprecated IKEv1 connections. IKEv1 will be '
+ 'removed in the future; please set key-exchange to IKEv2.'
+ )
for proposal, proposal_config in ike_config.get('proposal', {}).items():
if 'encryption' in proposal_config and 'prf' not in proposal_config:
# list of hash algorithms that cannot be mapped to an equivalent PRF