Site-to-Site Ipsec: Allow only traffic from one direction
Hi,
I have successfully setup site-to-site vpn between FG60D and Mikrotik router. The tunnel is up and running and is setup using policy route vpn.
Now i would like to block traffic coming from mikrotik-> FG. Is there any way of doing it with policy based vpn. I have even setup a block rule which block traffic from mt->fg but it doesn't seem to work. Looking at the logs it looks like the packets which comes from mt hits the ipsec rule and gets routed. I even tried to move the block rule above the ipsec rule but still had no luck.
I read the following in one of the manual "The source address that you choose for the security policy identifies from where outbound cleartext IP packets may originate, and also defines the local IP address or addresses that a remote server or client will be allowed to access through the VPN tunnel."
Can anyone help me with this
Thanks
