IPsec Port-override vs port-strict

Hi,

in the wiki i can read the following:

port-override – generate policies and force policy to use any port (old behavior)
port-strict – use ports from peer’s proposal, which should match peer’s policy

Can someone explain me the difference ? What means ports from peers proposal ? can i pin the communication to a networkport ?
what means “old behavior” ? Changed in mikrotik or change in standard ?

for a Windows 10 Client i can only user port-override in my tests.

Thanks for help !

port override is an old RouteOS behavior when there was only option to enable or disable “generate-policy”.
Port-strict is preferred since policy is mapped not just to ip address but also to port

thanks for reply.

i have made a typo in my post. i need to use port-override not port-strict for windows 10!

so what means port policy ? what port is defined by policy ? And why it does not work with windows ?


best regards

thanks for reply.

i have made a typo in my post. i need to use port-override not port-strict for windows 10!

so what means port policy ? what port is defined by policy ? And why it does not work with windows ?


best regards