[strongSwan] firewall configuration on Linux for IKE and dpd?

Thu May 27 14:49:37 CEST 2021

Hi folks,

I wonder if it is reasonable to use connection tracking for
500/udp and 4500/udp in the iptables configuration, esp.
wrt dead peer detection?

Your thoughts on this?


