I understand I need to create a blackhole DNAT to block inbound IPSec traffic. What I also need to do is allow a few endpoints to establish a tunnel. To me, this means I need two NAT rules -- one to passthru legit IPSec and the other to blackhole.
I've created two DNAT rules but the passthru rule isn't being matched. Before I turn up the blackhole DNAT I want to make sure the legit traffic will match the correct translation. Screenshot of the passthru NAT attached. Thanks.
Jack
This thread was automatically locked due to age.