Project

General

Profile

Actions

Bug #3794

closed

Re-orderable IPsec

Added by Robert Middleswarth over 9 years ago. Updated almost 9 years ago.

Status:
Duplicate
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
-
Start date:
09/15/2010
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
All
Affected Architecture:

Description

Allow IPSec tunnel order to be changed much like Firewall Rules can be re-ordered. The purpose is to give one tunnel priority over another in cases where you have overlapping subnets. For example you need 192.168.100.0/24 to go to destination A and 192.168.0.0/16 to go to destination B. Currently you have to delete all tunnels and re-create them in the proper order so the /24 is listed before the /16. I would expect this to work the same as static routes or at least have the option to manual tweaking the routing. The option that seems to work is deleting the /16 VPN and adding in the /24 get it working then adding back in the /16 network. Resulting in downtime and a lot of extra work.

Thanks
Robert

Actions

Also available in: Atom PDF