Navigation

    Netgate Discussion Forum
    • Register
    • Login
    • Search
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search

    Is it possible to proto/port limit ipsec [transport mode] through the web GUI?

    IPsec
    3
    3
    470
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E
      eroper last edited by

      I haven't been able to find a way to do it, but I'd like to set up an ipsec transport for a particular remote host, protocol and port combination, leaving all other traffic alone.

      It looks like strongswan may support the syntax directly in ipsec.conf, but I can't find a way to do it via. the GUI. Is this an oversight on my part, is it a new feature request, or am I misunderstanding the strongswan examples?:

      leftsubnet = <ip subnet="">[[<proto port="">]][,…]
      leftsubnet=10.0.0.1[tcp/http]
      leftsubnet=10.0.0.2[icmp/%any]

      Thanks!</proto></ip>

      1 Reply Last reply Reply Quote 0
      • E
        eri-- last edited by

        It will come for 2.3 for sure.

        1 Reply Last reply Reply Quote 0
        • D
          dayer last edited by

          Hi,

          I'm not sure about open a new topic for this feature.
          Is it already implemented? Could it be achieved with any rule?

          Regards.

          1 Reply Last reply Reply Quote 0
          • First post
            Last post

          Products

          • Platform Overview
          • TNSR
          • pfSense Plus
          • Appliances

          Services

          • Training
          • Professional Services

          Support

          • Subscription Plans
          • Contact Support
          • Product Lifecycle
          • Documentation

          News

          • Media Coverage
          • Press
          • Events

          Resources

          • Blog
          • FAQ
          • Find a Partner
          • Resource Library
          • Security Information

          Company

          • About Us
          • Careers
          • Partners
          • Contact Us
          • Legal
          Our Mission

          We provide leading-edge network security at a fair price - regardless of organizational size or network sophistication. We believe that an open-source security model offers disruptive pricing along with the agility required to quickly address emerging threats.

          Subscribe to our Newsletter

          Product information, software announcements, and special offers. See our newsletter archive to sign up for future newsletters and to read past announcements.

          © 2021 Rubicon Communications, LLC | Privacy Policy