Virtual Private Networks (VPN)
IPsec
LR54 User Guide
467
status.
Format:
primary_ipsec_tunnel
backup_ipsec_tunnel
Optional: yes
Current value:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover
b. Set the primary IPsec tunnel:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover primary_
ipsec_tunnel
(config vpn ipsec tunnel backup_ipsec_tunnel)>
Configure SureLink active recovery for IPsec
You can configure the LR54 device to regularly probe IPsec tunnels to determine if the connection has
failed and take remedial action.
You can also configure the IPsec tunnel to fail over to a backup tunnel. See
for
further information.
Required configuration items
n
A valid IPsec configuration. See
for configuration instructions.
n
Enable IPsec active recovery.
n
The behavior of the LR54 device upon IPsec failure: either
l
Restart the IPsec interface
l
Reboot the device.
Additional configuration items
n
The interval between connectivity tests.
n
Whether the interface should be considered to have failed if one of the test targets fails, or all
of the test targets fail.
n
The number of probe attempts before the IPsec connection is considered to have failed.
n
The amount of time that the device should wait for a response to a probe attempt before
considering it to have failed.
To configure the LR54 device to regularly probe the IPsec connection:
Web
1. Log into Digi Remote Manager, or log into the local Web UI as a user with full Admin access
rights.
2. Access the device configuration:
Remote Manager: