Description

This article explains why the Loopback filter blocks VPN negotiations, even though the VPN tunnel does not use the loopback as its external interface.

Solution

This behavior is expected because the loopback is bound to the routing-engine. This means that any traffic reaching the device will be subject to the loopback filter if configured, including VPN traffic.

 

If you haven't configured the loopback filter, there's no need to add a term to allow VPN traffic. However, if you have configured the loopback filter and are using a default deny configuration, you'll need to explicitly allow IPSEC tunnel traffic depending on your setup.

Modification History

2024-07-06 : Article Created

Related Information

Firewall Filter Support on Loopback Interface