Project

General

Profile

Actions

Feature #16880

closed

Todo #16874: Improve handling of custom interface assignments

Extend the LAN bypass option for IPsec to all LAN subnets

Added by Marcos M 24 days ago. Updated 1 day ago.

Status:
Resolved
Priority:
Normal
Assignee:
Category:
IPsec
Target version:
Start date:
Due date:
% Done:

100%

Estimated time:
Plus Target Version:
26.10
Release Notes:
Default

Description

The option "Auto-exclude LAN address" at VPN > IPSec > Advanced Settings only applies to a single LAN interface. Update the feature to auto-exclude subnets from any LAN interface.

Actions #1

Updated by Marcos M 24 days ago

  • Private changed from No to Yes
Actions #2

Updated by Marcos M 23 days ago

  • Status changed from New to Feedback
  • Target version set to CE-Next
  • Private changed from Yes to No
  • Plus Target Version set to Plus-Next
Actions #3

Updated by Marcos M 23 days ago

  • % Done changed from 0 to 100
Actions #4

Updated by Alhusein Zawi 1 day ago

A non-default LAN subnet has been added.

connections {
bypass {
remote_addrs = 127.0.0.1
children {
bypasslan {
local_ts = 192.168.1.0/24,172.18.99.0/24
remote_ts = 192.168.1.0/24,172.18.99.0/24
mode = pass
start_action = trap
}
}
}

26.10-DEVELOPMENT (amd64)
built on Wed Jul 1 17:42:00 UTC 2026
FreeBSD 16.0-CURRENT

Actions #5

Updated by Marcos M 1 day ago

  • Target version changed from CE-Next to 2.9.0
  • Plus Target Version changed from Plus-Next to 26.10
Actions #6

Updated by Marcos M 1 day ago

  • Status changed from Feedback to Resolved
Actions

Also available in: Atom PDF