IPSec Routing/Firewall Issues
James Bewley <[email protected]>
| Newsgroups | gmane.comp.security.ipcop.user |
|---|---|
| Message-ID | <CALgqCCko1L3h_tK+pR25_RTGQCxWr2hBHLkjSDsosv=mb26G7A@mail.gmail.com> |
Hi, I am using IPSec on IPCop to route traffic to a remote network behind a Cisco ASA. It is working but there are a couple of issue I am having with the finer details of routing/firewall configuration. Issue 1: I need to route to multiple remote subnets but the UI doesn't appear to allow this? Issue 2: Applying firewall rules to the inbound traffic from the IPSec tunnel doesn't appear to work the same as other interfaces. I would expect to add route to DROP all traffic from the remote subnet destined for the GREEN network. If I do this then traffic stops in both directions because the rule isn't constrained to NEW TCP sessions. I therefore have to add another rule for every service I expect to use on the remote network and ALLOW traffic from the source port. Is this expected? Best, James ------------------------------------------------------------------------------ Find and fix application performance issues faster with Applications Manager Applications Manager provides deep performance insights into multiple tiers of your business applications. It resolves application problems quickly and reduces your MTTR. Get your free trial! https://ad.doubleclick.net/ddm/clk/302982198;130105516;z _______________________________________________ IPCop-user mailing list [email protected] Manage your subscription or unsubscribe https://lists.sourceforge.net/lists/listinfo/ipcop-user