Home/Support/Support Forum/How to allow only ssh and ftp over vpn tunnel between two TransPort WR11
Welcome to Digi Forum, where you can ask questions and receive answers from other members of the community.

How to allow only ssh and ftp over vpn tunnel between two TransPort WR11

0 votes
asked May 8, 2018 in Digi TransPort by bradc44 New to the Community (0 points)

Please log in or register to answer this question.

1 Answer

0 votes
you can add firewall rules that only allow set traffic in and out of the tunnel

0 20 #Allow any traffic within an IPSEC tunnel in both directions
0 21 pass break end oneroute any

this is from the default rules.
where your ipsec ia enabled you need to add firewall on

so to allow traffic to ssh over the tunnel would be something like

pass out break end oneroute from any to any port=22 inspect-state

you might only need to enable it on one end

regards

James
answered May 8, 2018 by James.Wilson Veteran of the Digi Community (1,225 points)
...