• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Feature question: aliases for IPSEC Phase 2 entries

Scheduled Pinned Locked Moved Development
4 Posts 4 Posters 1.2k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • W
    whosmatt
    last edited by Jul 1, 2017, 10:10 PM

    Forgive me as this has certainly been asked elsewhere.

    Has there been any recent thought to the ability to use aliases in Phase 2 entries?  This would somewhat put pfSense on par with, say, the ASA, where tunnels can be defined using logical groups of objects (those being hosts or subnets).

    I see that https://redmine.pfsense.org/issues/946 addresses the same question starting 6 years ago.  Just wondering if there's any current movement on this front.  I actually talked one of my coworkers who is more on the developer side of things (though his title is sysadmin, as is mine) into writing this into PHP back in the 2.1.x days but we never took it any further than some lab testing.

    Just curious :)

    1 Reply Last reply Reply Quote 1
    • M
      markdegroot
      last edited by Jul 26, 2017, 10:11 AM

      We are having the same issue. We want to have IPSec tunnels to three hosts instead of a complete subnet. For now we create one Phase2 rule per host. It would be great if we could just add one aliases for the three hosts.

      1 Reply Last reply Reply Quote 1
      • M
        mrpsycho
        last edited by Apr 26, 2018, 2:56 PM

        +100500 for this feature.

        this is very and very useful feature.

        because here, in russia, we suffer from our f*ucked up government… and ipsec one of the fastest solution to build bridges between countries.

        and this is needed to allow our "whitelisted" traffic to stay in russia.

        1 Reply Last reply Reply Quote 1
        • W
          wildchild84
          last edited by Jul 26, 2018, 8:37 AM

          I agree as well, please add it! I have several customers with this configuration and I really need this feature. I have to manual add more than 20 subnets on each server, pretty annoying although I would have an Alias ready for that.

          1 Reply Last reply Reply Quote 1
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
            [[user:consent.lead]]
            [[user:consent.not_received]]