Before anyone asks:
1. I'm already using OpenVPN and Wireguard for LAN Access; this is a question out of curiosity since I am tinkering with IPsec for fun (though if it does allow me to access devices on the LAN, it would be a helpful backup seeing as it's natively implemented into Windows and Android).
2. I'm not installing Merlin or OpenWRT; not only do I not really have a use case for third party firmware yet but even if I did, I'm using a GT-BE98 Pro which AFAIK is so new it doesn't even have third party firmware available. Also, I'm pretty sure those developers haven't bothered with IPsec.
Asus IPsec forces all remote clients into the 10.10.10.0/24 range and there is no option to push the LAN to them like there is with OpenVPN and Wireguard. As far as I can tell, Asus' IPsec implementation is only good for routing remote internet-bound traffic through the router, which would only be useful for security in public areas at best. Is there actually some way to account for this limitation via firewall rules and/or static routes?
1. I'm already using OpenVPN and Wireguard for LAN Access; this is a question out of curiosity since I am tinkering with IPsec for fun (though if it does allow me to access devices on the LAN, it would be a helpful backup seeing as it's natively implemented into Windows and Android).
2. I'm not installing Merlin or OpenWRT; not only do I not really have a use case for third party firmware yet but even if I did, I'm using a GT-BE98 Pro which AFAIK is so new it doesn't even have third party firmware available. Also, I'm pretty sure those developers haven't bothered with IPsec.
Asus IPsec forces all remote clients into the 10.10.10.0/24 range and there is no option to push the LAN to them like there is with OpenVPN and Wireguard. As far as I can tell, Asus' IPsec implementation is only good for routing remote internet-bound traffic through the router, which would only be useful for security in public areas at best. Is there actually some way to account for this limitation via firewall rules and/or static routes?