Project

General

Profile

Actions

Bug #8686

open

IPsec VTI: Assigned interface firewall rules are never parsed

Added by Steve Wheeler over 6 years ago. Updated over 1 year ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
IPsec
Target version:
-
Start date:
07/24/2018
Due date:
% Done:

0%

Estimated time:
Plus Target Version:
Release Notes:
Affected Version:
2.4.4
Affected Architecture:
All

Description

Traffic entering an assigned VTI interface never hits firewall rules on that specific interface tab even if they are present.
Traffic must still be passed on the main IPsec tab.
This is potentially confusing, it's not the expected behavior that other interface types exhibit.


Files

ipsec_filtermode.diff (6.21 KB) ipsec_filtermode.diff Jim Pingle, 02/04/2021 01:15 PM

Related issues

Related to Bug #4479: Firewall rules won't match GRE interface after applying IPSEC transport encryption on GRE tunnelNewLuiz Souza02/27/2015

Actions
Related to Regression #15430: Interface-bound state policy does not handle IPsec VTI traffic as expected when filtering on ``enc0`` interfaceResolvedMarcos M

Actions
Actions

Also available in: Atom PDF