![Digi IX20 User Manual Download Page 289](http://html.mh-extra.com/html/digi/ix20/ix20_user-manual_2496666289.webp)
Virtual Private Networks (VPN)
IPsec
IX20 User Guide
289
Format:
primary_ipsec_tunnel
backup_ipsec_tunnel
Optional: yes
Current value:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover
b. Set the primary IPsec tunnel:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover primary_
ipsec_tunnel
(config vpn ipsec tunnel backup_ipsec_tunnel)>
4. Save the configuration and apply the change:
(config vpn ipsec tunnel backup_ipsec_tunnel)> save
Configuration saved.
>
5. Type
exit
to exit the Admin CLI.
Depending on your device configuration, you may be presented with an
Access selection
menu
. Type
quit
to disconnect from the device.
Configure SureLink active recovery for IPsec
You can configure the IX20 device to regularly probe IPsec client connections to determine if the
connection has failed and take remedial action.
You can also configure the IPsec tunnel to fail over to a backup tunnel. See
for
further information.
Required configuration items
n
A valid IPsec configuration. See
for configuration instructions.
n
Enable IPsec active recovery.
n
The behavior of the IX20 device upon IPsec failure: either
l
Restart the IPsec interface
l
Reboot the device.
Additional configuration items
n
The interval between connectivity tests.
n
Whether the interface should be considered to have failed if one of the test targets fails, or all
of the test targets fail.
n
The number of probe attempts before the IPsec connection is considered to have failed.
n
The amount of time that the device should wait for a response to a probe attempt before
considering it to have failed.
To configure the IX20 device to regularly probe the IPsec connection: