OPNsense Beginner to Professional by Julio Cesar Bueno de Camargo

OPNsense Beginner to Professional by Julio Cesar Bueno de Camargo

Author:Julio Cesar Bueno de Camargo
Language: eng
Format: epub
Publisher: Packt Publishing Pvt Ltd
Published: 2022-05-19T00:00:00+00:00


IPsec routed tunnel (VTI)

The routed tunnel configuration uses a Virtual Tunnel Interface (VTI), so you will probably hear people calling this IPsec configuration just VTI. The main difference with this kind of configuration is that instead of using a policy based on routes managed by the IPsec daemon and the kernel, it will use installed routes on the operating system using the virtual interface. If you already use OpenVPN tunnels, it will sound familiar to you; the working principle is almost the same.

Following the steps from the IPsec BINAT example, you can alter a few steps to change it from a policy-based to a route-based tunnel. You don't need to follow the NAT rule steps and change the network address to the existing local networks configured in Site A and B firewalls.

Let's go through the steps:

Follow the steps for Phase 1 as discussed in the Creating a new IPSec tunnel section, leaving the following options unchecked:Install policy

Disable Rekey

Disable Reauth

Dead Peer Detection

Disable NAT Traversal: NAT Traversal: Disabled



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.