Forum Discussion
LTM 13.0 Unable to create IPSec with traffic domain other than 0
Hi,
The “interface” mode IPSec is working between route-domains.
But only one traffic-selector can be associated to IPSec channel so it is unusable if you want to use more encrypted subnets.
But only one traffic-selector can be associated to IPsec channel
True.
so it is unusable if you want to use more encrypted subnets.
Not quite true.
Interface mode has an additional hidden option whereby you can tell your BIG-IP to ignore the selector and obey the routing table. This means that you can bring up a tunnel using any old traffic-selector and then control the traffic that goes over the tunnel using dynamic or static routing.
For more information, please take a look at K31553030.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com