Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Road warriors with specific IP and rules

    Scheduled Pinned Locked Moved IPsec
    4 Posts 3 Posters 1.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • X
      xtofh
      last edited by

      Hi,

      With OpenVPN I can assign a specific IP to a road warrior (on linux, client specific config or ccd).

      Is there any way to do something similar with IPSec? I would like client X to always get ip 10.9.9.X and client Y to always get ip 10.9.9.Y..

      That way I could make specific rules for specific clients (allowing/disallowing certain services) and not have 1 "big" rule set that applies to all Road Warriors.

      I doubt it's possible but I (certainly) might have looked over it..ย  8)

      Thanks in advance,

      Kristof.

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        Unfortunately, static client IPs are not possible with IPsec.

        Works fine with OpenVPN though (Client-Specific Overrides tab)

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        1 Reply Last reply Reply Quote 0
        • C
          ConfusedUser
          last edited by

          I just saw this old post and I was trying to figure out the same thing.

          I wonder if there are any other ways of assigning specific rules to specific groups of users (all client2site "road warriors") when using IPSec? Or do I have to use OpenVPN to achieve this?
          Is there no possible workaround?

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            There are not currently any methods of making "multiple" groups of IPsec users, nor any way of assigning them IPs from separate pools from the server.

            So you would need OpenVPN for that sort of scenario.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.