ER707-M2 - IPsec ports open to internet, firewall not restricting

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

ER707-M2 - IPsec ports open to internet, firewall not restricting

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
ER707-M2 - IPsec ports open to internet, firewall not restricting
ER707-M2 - IPsec ports open to internet, firewall not restricting
2024-10-28 03:52:01 - last edited 2024-10-31 08:01:41
Model: ER707-M2  
Hardware Version: V1
Firmware Version: 1.2.3

Hi All,

 

I've recently switched to an Omada router after previously using Opnsense. I've noticed that the behavior for IPsec VPNs is different from what I've experienced with other firewall vendors.

 

Typically, other firewall vendors restrict the source IP for IPsec firewall rules to the destination IP specified in the configuration. However, Omada doesn’t seem to enforce this restriction, leaving IPsec ports (500 and 4500) exposed to the entire internet.

 

I'm wondering if there’s a way to limit this exposure, possibly using Gateway ACLs, or if there might be plans for a firmware update to address this.

 

Thanks!

  0      
  0      
#1
Options
1 Accepted Solution
Re:ER707-M2 - IPsec ports open to internet, firewall not restricting-Solution
2024-10-28 05:46:03 - last edited 2024-10-31 08:01:41

Hi @rquigley 

Thanks for posting in our business forum.

Using the ACL to limit that.

Exposing that port to the Internet does not hurt a thing since they don't have the keys to make a proper connection.

Recommended Solution
  2  
  2  
#2
Options
1 Reply
Re:ER707-M2 - IPsec ports open to internet, firewall not restricting-Solution
2024-10-28 05:46:03 - last edited 2024-10-31 08:01:41

Hi @rquigley 

Thanks for posting in our business forum.

Using the ACL to limit that.

Exposing that port to the Internet does not hurt a thing since they don't have the keys to make a proper connection.

Recommended Solution
  2  
  2  
#2
Options