Project

General

Profile

Actions

Feature #16880

closed
MM MM

Todo #16874: Improve handling of custom interface assignments

Extend the LAN bypass option for IPsec to all LAN subnets

Feature #16880: Extend the LAN bypass option for IPsec to all LAN subnets

Added by Marcos M 3 months ago. Updated about 1 month ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
IPsec
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
26.10
Release Notes:
Default

Description

The option "Auto-exclude LAN address" at VPN > IPSec > Advanced Settings only applies to a single LAN interface. Update the feature to auto-exclude subnets from any LAN interface.

MM Updated by Marcos M 3 months ago Actions #1

  • Private changed from No to Yes

MM Updated by Marcos M 3 months ago Actions #2

  • Status changed from New to Feedback
  • Target version set to CE-Next
  • Private changed from Yes to No
  • Plus Target Version set to Plus-Next

MM Updated by Marcos M 3 months ago Actions #3

  • % Done changed from 0 to 100

AZ Updated by Alhusein Zawi 2 months ago Actions #4

A non-default LAN subnet has been added.

connections {
bypass {
remote_addrs = 127.0.0.1
children {
bypasslan {
local_ts = 192.168.1.0/24,172.18.99.0/24
remote_ts = 192.168.1.0/24,172.18.99.0/24
mode = pass
start_action = trap
}
}
}

26.10-DEVELOPMENT (amd64)
built on Wed Jul 1 17:42:00 UTC 2026
FreeBSD 16.0-CURRENT

MM Updated by Marcos M 2 months ago Actions #5

  • Target version changed from CE-Next to 2.9.0
  • Plus Target Version changed from Plus-Next to 26.10

MM Updated by Marcos M 2 months ago Actions #6

  • Status changed from Feedback to Resolved

MM Updated by Marcos M about 1 month ago Actions #7

  • Target version changed from 2.9.0 to CE-Next
Actions

Also available in: Atom