Actions
Bug #8239
closedIf IPsec bypasslan is enabled while the LAN interface is disabled, all traffic bypasses IPsec
Start date:
12/27/2017
Due date:
% Done:
100%
Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.4.x
Affected Architecture:
All
Description
If IPsec bypasslan is enabled while the LAN interface is disabled, all traffic bypasses IPsec because it makes an SPD for 0.0.0.0/0 to 0.0.0.0/0 set to 'none', which effectively makes all traffic skip IPsec processing.
bypasslan should be skipped if LAN is disabled or if LAN does not have an IP address
Actions