LINUX.ORG.RU

История изменений

Исправление intelfx, (текущая версия) :

/ip firewall nat
add action=accept chain=srcnat comment="Skip SNAT for IPsec-out" ipsec-policy=out,ipsec

/ip firewall filter
add action=accept chain=input comment="accept from IPsec VPN" ipsec-policy=in,ipsec
add action=accept chain=forward comment="forward to IPsec VPN (must be before fasttrack)" ipsec-policy=out,ipsec
add action=accept chain=forward comment="forward from IPsec VPN (must be before fasttrack)" ipsec-policy=in,ipsec

Исходная версия intelfx, :

/ip firewall nat
add action=accept chain=srcnat comment="Skip SNAT for IPsec-out" ipsec-policy=out,ipsec log-prefix=ipsec-skip-snat

/ip firewall filter
add action=accept chain=input comment="accept from IPsec VPN" ipsec-policy=in,ipsec
add action=accept chain=forward comment="forward to IPsec VPN (must be before fasttrack)" ipsec-policy=out,ipsec
add action=accept chain=forward comment="forward from IPsec VPN (must be before fasttrack)" ipsec-policy=in,ipsec