Skip to content

Conversation

@brada4
Copy link

@brada4 brada4 commented May 31, 2025

ip4 part never served any purpose except confusing users eg #53
Permit only IKE conformant to RFC, ip4 NAT traversal has different port and terminating on the router can be handled by ipsec policy filtering.

Fixes: openwrt/openwrt@8fb39f1

Signed-off-by: Andris PE neandris@gmail.com

ip4 part never served any purpose except confusing users
eg openwrt#53
Permit only IKE conformant to RFC, ip4 NAT traversal has different port
and terminating on the router can be handled by ipsec policy filtering.

Fixes: openwrt/openwrt@8fb39f1
Signed-off-by: Andris PE <neandris@gmail.com>
brada4 added a commit to brada4/openwrt that referenced this pull request Dec 11, 2025
Do not accept unsolicited ICMP echo reply. It is implied by conntrack
state from request already. cf openwrt/firewall4#44
Also exemplified by ipv4 ping rule

Limit peer-to-peer ipsec to ipv6 only as stated in original "ipv6 cpe
requirements" cf openwrt/firewall4#65

Signed-off-by:
brada4 added a commit to brada4/openwrt that referenced this pull request Dec 11, 2025
Do not accept unsolicited ICMP echo reply. It is implied by conntrack
state from request already. cf openwrt/firewall4#44
Also exemplified by ipv4 ping rule

Limit peer-to-peer ipsec to ipv6 only as stated in original "ipv6 cpe
requirements" cf openwrt/firewall4#65

Signed-off-by: Andris PE <neandris@gmail.com>
brada4 added a commit to brada4/openwrt that referenced this pull request Dec 11, 2025
Do not accept unsolicited ICMP echo reply. It is implied by conntrack
state from request already. cf openwrt/firewall4#44
Also exemplified by ipv4 ping rule

Limit peer-to-peer ipsec to ipv6 only as stated in original "ipv6 cpe
requirements" cf openwrt/firewall4#65

Signed-off-by: Andris PE <neandris@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant