ikev1, auto=route narrows subnet based TS to protocol port used
When IKEv1, auto=route and /24 subnets in both sites, auto=route incorrectly narrows Traffic Selectors.
When traffic is initiated, IPsec SA is narrowed/negotiated only for the protocol/port used but not for subnets.
Example: using ssh from site1 to site2, TS is
172.16.60.10/32[tcp/ssh] === 172.16.50.10/32[tcp/49298]
Expected behaviour is that TS would be
172.16.60.0/24[any] === 172.16.50.0/24[any]
If auto=start is used, TS is as expected.
I think that bug was introduced in an attempt to
fix IKEv1 reauthentication (where we do want to reuse the smaller TS
in case of narrowing).