Feature #946
open
Allow aliases to be used to define IPsec phase 2 networks
Added by Jim Pingle over 15 years ago.
Updated about 1 month ago.
Description
Eventually it would be nice to allow using aliases on the IPsec phase 2 definition screen for local and remote networks. It would be an easy and clean way to avoid having to manually make many entries that are identical except for the subnet definitions.
The GUI code would just need to add the alias autcomplete mechanism to the "Address" field, perhaps either by sharing the "Network" choice in type, so it would be "Network or alias", or use a choice for just "Alias". We might need to restrict it to host and network alias types. The backend would just need to generate the appropriate pairings of phase 2 declarations in racoon.conf, matching each entry in the local alias/network to an entry in the remote alias/network.
- Target version changed from Future to 2.3
This is possible to implement easily now that strongswan is used.
- Assignee set to Ermal Luçi
- Assignee changed from Ermal Luçi to Renato Botelho
- Target version changed from 2.3 to Future
It will be great see it in next release of pfSense.
Today I must create ~100 tunnels phase 2.
I had to create 5 my internal networks to external subnets.... and I must do it one by one.
With aliases I could create alias: my_local_network for example and route it all to external subnets much easier.
Has been over 7 year now, it will be good to have that option?
Is there an update on this?
- Assignee deleted (
Renato Botelho)
It would be great if this could get integrated
Chiming in, this would be a great feature to implement; the ability to use alias objects in IPsec phase 2 local networks and remote networks to mitigate the need to create 10s or in Grzegorz's case, 100s of P2s for a single tunnel with multiple P2s.
Thank you for all the hard work that is put into pfSense!
Also available in: Atom
PDF