Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    How to enable Tunnel Isolation Mode

    Scheduled Pinned Locked Moved IPsec
    4 Posts 2 Posters 714 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D
      dabenavidesd
      last edited by

      Dear all:
      can you enlight me how to enable Tunnel isolation mode lease. Thanks in advance

      1 Reply Last reply Reply Quote 0
      • jimpJ
        jimp Rebel Alliance Developer Netgate
        last edited by

        What exactly do you mean by "Tunnel isolation mode"?

        Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

        Need help fast? Netgate Global Support!

        Do not Chat/PM for help!

        D 1 Reply Last reply Reply Quote 0
        • D
          dabenavidesd @jimp
          last edited by

          @jimp Hi: thanks for your answer, but still not sure if that's what I need.
          My problem is I'm having some intermittence in IPsec, so I want to diagnose if it's a problem with the encryption domains. From what I researched could be traffic being dropped intermittently because of tunnel configuration for multiple domains, so I want to isolate the failure.
          One way was as I found to make multiple IPsec with just one encryption domain each. So I found the tunnel isolation on Ipsec could be useful for that.

          1 Reply Last reply Reply Quote 0
          • jimpJ
            jimp Rebel Alliance Developer Netgate
            last edited by

            Sounds like what you want is "Split connections" in the P1 options.

            IKEv1 is always split -- each P2 gets its own separate configuration
            IKEv2 can combine traffic selectors and does so by default, so all your P2 configurations get lumped into a single configuration entry. This is more efficient and flexible, since it only needs to maintain one child SA for all traffic, but some other devices/services don't like it for various reasons.

            If you are using IKEv2 and check "Split Connections" then it creates a separate configuration for each P2 so they will be independent.

            Remember: Upvote with the ๐Ÿ‘ button for any user/post you find to be helpful, informative, or deserving of recognition!

            Need help fast? Netgate Global Support!

            Do not Chat/PM for help!

            1 Reply Last reply Reply Quote 0
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.