Коллеги, каким образом можно запретить исходящие Site-to-Site L2TP соединения без шифрования IPsec?
Текущие правила output не помогают:
add chain=output action=accept connection-state=established,related comment="Allow Established and Related connections"
add chain=output action=reject protocol=gre ipsec-policy=out,none reject-with=icmp-admin-prohibited comment="Block GRE/EoIP without IPsec"
add chain=output action=reject protocol=l2tp ipsec-policy=out,none reject-with=icmp-admin-prohibited comment="Block L2TP without IPsec"
add chain=output action=reject protocol=udp dst-port=1701 ipsec-policy=out,none reject-with=icmp-admin-prohibited comment="Block L2TP without IPsec"