Virtual Private Networks (VPN)
IPsec
IX14 User Guide
560
status.
Format:
primary_ipsec_tunnel
backup_ipsec_tunnel
Optional: yes
Current value:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover
b. Set the primary IPsec tunnel:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover primary_
ipsec_tunnel
(config vpn ipsec tunnel backup_ipsec_tunnel)>
Configure SureLink active recovery for IPsec
You can configure the IX14 device to regularly probe IPsec tunnels to determine if the connection has
failed and take remedial action.
You can also configure the IPsec tunnel to fail over to a backup tunnel. See
for
further information.
Required configuration items
n
A valid IPsec configuration. See
for configuration instructions.
n
Enable IPsec active recovery.
n
The behavior of the IX14 device upon IPsec failure: either
l
Restart the IPsec interface
l
Reboot the device.
Additional configuration items
n
The interval between connectivity tests.
n
Whether the interface should be considered to have failed if one of the test targets fails, or all
of the test targets fail.
n
The number of probe attempts before the IPsec connection is considered to have failed.
n
The amount of time that the device should wait for a response to a probe attempt before
considering it to have failed.
To configure the IX14 device to regularly probe the IPsec connection:
WebUI