IPsec tunnel initiating on the outside to loopback
So we currently have some IPsec tunnels that initate both on the inside and on the outside using our outside interface.
We want to move this to a loopback instead, so that our ISP is more free to make changes on our outside interface.
We're using 1800F version 7.2.9.
I'm struggling to understand if I have to do anything after we moved the tunnels to the loopback, so that they can both be initiated from the inside aswell as the outside.
I was thinking if I put the loopback interface in the same zone as outside interface and allow intra-zone traffic, is that a good sulotion that will work?
My other idea would be to create a firewall policy, that allows traffic coming from the outside interface, going into the loopback. Allowing remote VPN address as source.
If so, is it enough to allow IKE traffic on this rule, or do we need ESP aswell?
Thanks you!
