Quote from: Monviech (Cedrik) on October 03, 2023, 11:37:04 AM...
ATTENTION:
- With this setup, all filter rules (firewall rules) will match on the ipsecXX interfaces. NOT on the enc0 interface. All filtering on the enc0 was disabled, so policy based tunnels won't have firewall anymore.
The instructions say to add rules to "Firewall -> Rules -> IPsec", but I think they mean "Firewall -> Rules -> IPSECnn", which makes sense.
Quote- Please either use only VTI or only ENC0 tunnels, mixing them will leave one of them unable to filter in the firewall.
Is this still a thing? If so, then it's simply not possible to migrate your tunnels one at a time?