How would I configure a rule that applies ipsec policy only for a protocol/port but let other packets pass-through. Can I just specify %any in protoport? Thanks -------------- next part -------------- An HTML attachment was scrubbed... URL: <https://lists.libreswan.org/pipermail/swan/attachments/20190417/07b91c26/attachment.html>