<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Random reminder that if you are exposing IKE to the Internet for static site-to-site tunnels, maybe allowlist only your peer endpoints and don&#x27;t allow full Internet access to them.]]></title><description><![CDATA[<p>Random reminder that if you are exposing IKE to the Internet for static site-to-site tunnels, maybe allowlist only your peer endpoints and don't allow full Internet access to them. Just a thought. If you aren't sure if you are exposed, today seems like a good day to find out.</p><p></p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">

<div class="card-body">
<h5 class="card-title">
<a href="https://www.shodan.io/search?query=port%3A500">
Just a moment...
</a>
</h5>
<p class="card-text line-clamp-3"></p>
</div>
<a href="https://www.shodan.io/search?query=port%3A500" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://www.shodan.io/favicon.ico" alt="favicon" class="not-responsive overflow-hiddden" style="max-width:21px;max-height:21px" />



<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(www.shodan.io)</span></p>
</a>
</div><p></p>]]></description><link>https://board.circlewithadot.net/topic/3483de7b-609e-40be-bacf-3e0592e1c7b0/random-reminder-that-if-you-are-exposing-ike-to-the-internet-for-static-site-to-site-tunnels-maybe-allowlist-only-your-peer-endpoints-and-don-t-allow-full-internet-access-to-them.</link><generator>RSS for Node</generator><lastBuildDate>Fri, 15 May 2026 01:52:32 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/3483de7b-609e-40be-bacf-3e0592e1c7b0.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 12 May 2026 13:49:33 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Random reminder that if you are exposing IKE to the Internet for static site-to-site tunnels, maybe allowlist only your peer endpoints and don&#x27;t allow full Internet access to them. on Wed, 13 May 2026 13:57:02 GMT]]></title><description><![CDATA[<p><span><a href="/user/nyanbinary%40infosec.exchange">@<span>nyanbinary</span></a></span> <span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> Mike asked for his return... he did not tell us why.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116093572746253175/statuses/116567613271544887</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/ap/users/116093572746253175/statuses/116567613271544887</guid><dc:creator><![CDATA[jackryder@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 13:57:02 GMT</pubDate></item><item><title><![CDATA[Reply to Random reminder that if you are exposing IKE to the Internet for static site-to-site tunnels, maybe allowlist only your peer endpoints and don&#x27;t allow full Internet access to them. on Wed, 13 May 2026 13:51:21 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> who is Ike &amp; why are we trying to keep them off the internet?</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/nyanbinary/statuses/116567590925401083</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/nyanbinary/statuses/116567590925401083</guid><dc:creator><![CDATA[nyanbinary@infosec.exchange]]></dc:creator><pubDate>Wed, 13 May 2026 13:51:21 GMT</pubDate></item><item><title><![CDATA[Reply to Random reminder that if you are exposing IKE to the Internet for static site-to-site tunnels, maybe allowlist only your peer endpoints and don&#x27;t allow full Internet access to them. on Tue, 12 May 2026 17:11:18 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> <span><a href="/user/fuzzyfuzzyfungus%40cyberplace.social" rel="nofollow noopener">@<span>fuzzyfuzzyfungus</span></a></span> </p><p>Thanks to DYNDNS, my home  based S2S WireGuard tunnels only allow the specific FQDN I need. </p><p>ISP DHCP based IP change is roughly a 1hr downtime window.  My ZFS replications can handle that fine.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/kajer/statuses/116562714838778832</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/kajer/statuses/116562714838778832</guid><dc:creator><![CDATA[kajer@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 17:11:18 GMT</pubDate></item><item><title><![CDATA[Reply to Random reminder that if you are exposing IKE to the Internet for static site-to-site tunnels, maybe allowlist only your peer endpoints and don&#x27;t allow full Internet access to them. on Tue, 12 May 2026 13:59:28 GMT]]></title><description><![CDATA[<p><span><a href="/user/fuzzyfuzzyfungus%40cyberplace.social" rel="nofollow noopener">@<span>fuzzyfuzzyfungus</span></a></span> As of today it's a general good practice reminder. But we never know what tomorrow may bring.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116561960563339214</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cR0w/statuses/116561960563339214</guid><dc:creator><![CDATA[cr0w@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 13:59:28 GMT</pubDate></item><item><title><![CDATA[Reply to Random reminder that if you are exposing IKE to the Internet for static site-to-site tunnels, maybe allowlist only your peer endpoints and don&#x27;t allow full Internet access to them. on Tue, 12 May 2026 13:57:24 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> Is this a good practice reminder apropos of nothing super particular; or has one of the Enterprise Gateway Widget vendors covered themselves in glory again?</p>]]></description><link>https://board.circlewithadot.net/post/https://cyberplace.social/users/fuzzyfuzzyfungus/statuses/116561952415648368</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://cyberplace.social/users/fuzzyfuzzyfungus/statuses/116561952415648368</guid><dc:creator><![CDATA[fuzzyfuzzyfungus@cyberplace.social]]></dc:creator><pubDate>Tue, 12 May 2026 13:57:24 GMT</pubDate></item><item><title><![CDATA[Reply to Random reminder that if you are exposing IKE to the Internet for static site-to-site tunnels, maybe allowlist only your peer endpoints and don&#x27;t allow full Internet access to them. on Tue, 12 May 2026 13:53:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/cr0w%40infosec.exchange">@<span>cR0w</span></a></span> Hmm.</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/561/937/911/768/360/original/0c443b0a7d34e3c1.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116561938369271790</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/Sempf/statuses/116561938369271790</guid><dc:creator><![CDATA[sempf@infosec.exchange]]></dc:creator><pubDate>Tue, 12 May 2026 13:53:50 GMT</pubDate></item></channel></rss>