firewalld: Block non-ESP packets on interface in GNU/Linux similar to OpenBSD
I am trying to "enforce" IPSec (StrongSwan) traffic on openSUSE.
On OpenBSD, with the IKE daemon iked and the packet filter pf, I employ a ruleset like the following, to ensure only encapsulated traffic passes the interface, prac… Continue reading firewalld: Block non-ESP packets on interface in GNU/Linux similar to OpenBSD