<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How can I exclude one IP from a phase 2 entry]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I have a really annoying problem that I am trying to resolve.  Assume the following subnets.</p>
<p dir="auto">Site A Internal: 10.10.0.0/16<br />
Site B Internal: 10.50.0.0/16<br />
Site B DMZ: x.y.z.0/24  ( Where this is a valid public subnet).</p>
<p dir="auto">I have an ipsec vpn setup.  The first phase 2 entry  allows 10.10.0.0/16 and 10.50.0.0/15 to talk.  This works perfect.<br />
I then made a second phase 2,  to allow 10.10.0.0/16 and x.y.z.0/24 to communicate using the tunnel.  This worked ok too.</p>
<p dir="auto">The problem I'm having is that i have a handful of IP's spread out randomly on site B DMZ that I need to exclude from the tunnel.</p>
<p dir="auto">My current method of doing this is to split the phase 2 into 10 different entries, so that I work around the ips.  This is very painful to manage, and if a new ip gets added, then I need to break the vpn again while i rework the phase 2 entries.  Is there a better solution for this?</p>
<p dir="auto">I can upgrade to 2.1 if that resolves this.</p>
]]></description><link>https://forum.netgate.com/topic/62565/how-can-i-exclude-one-ip-from-a-phase-2-entry</link><generator>RSS for Node</generator><lastBuildDate>Fri, 12 Jun 2026 13:49:28 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/62565.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 08 Nov 2013 14:50:35 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How can I exclude one IP from a phase 2 entry on Mon, 11 Nov 2013 16:08:15 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/artimus">@<bdi>artimus</bdi></a>:</p>
<blockquote>
<p dir="auto">If I block the ip with a fw rule, then it will be blocked.  I need the ip to connect to the remote side, but just not over the vpn.</p>
</blockquote>
<p dir="auto">The traffic will only be blocked on the VPN interface. If the traffic was passing in over the WAN or another interface, you could pass the traffic. If it's a routing issue, that could be complicated as a tunnel will trump a local route, but that would be an unusual situation.</p>
]]></description><link>https://forum.netgate.com/post/429146</link><guid isPermaLink="true">https://forum.netgate.com/post/429146</guid><dc:creator><![CDATA[dotdash]]></dc:creator><pubDate>Mon, 11 Nov 2013 16:08:15 GMT</pubDate></item><item><title><![CDATA[Reply to How can I exclude one IP from a phase 2 entry on Mon, 11 Nov 2013 15:09:03 GMT]]></title><description><![CDATA[<p dir="auto">If I block the ip with a fw rule, then it will be blocked.  I need the ip to connect to the remote side, but just not over the vpn.</p>
]]></description><link>https://forum.netgate.com/post/429139</link><guid isPermaLink="true">https://forum.netgate.com/post/429139</guid><dc:creator><![CDATA[artimus]]></dc:creator><pubDate>Mon, 11 Nov 2013 15:09:03 GMT</pubDate></item><item><title><![CDATA[Reply to How can I exclude one IP from a phase 2 entry on Sun, 10 Nov 2013 17:44:42 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/dotdash">@<bdi>dotdash</bdi></a>:</p>
<blockquote>
<p dir="auto">Any reason you can't tunnel the whole subnet and control access via firewall rules?</p>
</blockquote>
<p dir="auto">This is what I recently did when I was having Active Directory replication issues and wanted to make sure the it didn't magically start working on the broken systems while I was building new boxes.</p>
]]></description><link>https://forum.netgate.com/post/428994</link><guid isPermaLink="true">https://forum.netgate.com/post/428994</guid><dc:creator><![CDATA[jasonlitka]]></dc:creator><pubDate>Sun, 10 Nov 2013 17:44:42 GMT</pubDate></item><item><title><![CDATA[Reply to How can I exclude one IP from a phase 2 entry on Fri, 08 Nov 2013 15:18:03 GMT]]></title><description><![CDATA[<p dir="auto">Any reason you can't tunnel the whole subnet and control access via firewall rules?</p>
]]></description><link>https://forum.netgate.com/post/428763</link><guid isPermaLink="true">https://forum.netgate.com/post/428763</guid><dc:creator><![CDATA[dotdash]]></dc:creator><pubDate>Fri, 08 Nov 2013 15:18:03 GMT</pubDate></item></channel></rss>