Tunnel Type |
|
Interface Name (1..255) |
Name of the interface.
|
Description
|
Enter a description for the interface.
|
Tracker |
By default, a tracker is attached to monitor the health of tunnels.
|
Tunnel Source Interface |
Name of the source interface of the tunnel. This interface should be an egress interface and is typically the internet-facing
interface. The tunnel source interface supports loopback.
|
Data-Center |
For a primary data center, click Primary, or for a secondary data center, click Secondary. Tunnels to the primary data center serve as active tunnels, and tunnels to the secondary data center serve as back-up tunnels.
|
Advanced Options (Optional)
|
Shutdown |
Click the radio button to enable this option.
Default: Disabled
|
Enable Tracker
|
Click the radio button to enable this option.
|
IP MTU |
Specify the maximum MTU size of packets on the interface.
Range: 576 to 2000 bytes
Default: 1400 bytes
|
TCP MSS |
Specify the maximum segment size (MSS) of TPC SYN packets. By default, the MSS is dynamically adjusted based on the interface
or tunnel MTU such that TCP SYN packets are never fragmented.
Range: 500 to 1460 bytes
Default: None
|
DPD Interval |
Specify the interval for Internet Key Exchange (IKE) to send Hello packets on the connection.
Range: 10 to 3600 seconds
Default: 10
|
DPD Retries |
Specify the number of seconds between Dead Peer Detection (DPD) retry messages if the DPD retry message is missed by the peer.
If a peer misses a DPD message, the router changes the state and sends a DPD retry message. The message is sent at a faster
retry interval, which is the number of seconds between DPD retries. The default DPD retry message is sent every 2 seconds.
The tunnel is marked as down after five DPD retry messages are missed.
Range: 2 to 60 seconds
Default: 3
|
IKE
|
IKE Rekey Interval |
Specify the interval for refreshing IKE keys.
Range: 3600 to 1209600 seconds (1 hour to 14 days)
Default: 14400 seconds
|
IKE Cipher Suite |
Specify the type of authentication and encryption to use during IKE key exchange.
Choose one of the following:
-
AES 256 CBC SHA1
-
AES 256 CBC SHA2
-
AES 128 CBC SHA1
-
AES 128 CBC SHA2
Default: AES 256 CBC SHA1
|
IKE Diffie-Hellman Group |
Specify the Diffie-Hellman group to use in IKE key exchange, whether IKEv1 or IKEv2.
|
IPSec
|
IPsec Rekey Interval |
Specify the interval for refreshing IPsec keys.
Range: 3600 to 1209600 seconds (1 hour to 14 days)
Default: 3600 seconds
|
IPsec Replay Window |
Specify the replay window size for the IPsec tunnel.
Options: 64, 128, 256, 512, 1024, 2048, or 4096 packets.
Default: 512
|
IPsec Cipher Suite |
Specify the authentication and encryption to use on the IPsec tunnel.
Options:
-
AES 256 CBC SHA1
-
AES 256 CBC SHA 384
-
AES 256 CBC SHA 256
-
AES 256 CBC SHA 512
-
AES 256 GCM
Default: AEM 256 GCM
|
Perfect Forward Secrecy |
Specify the Perfect Forward Secrecy (PFS) settings to use on the IPsec tunnel. Choose one of the following Diffie-Hellman
prime modulus groups:
-
Group-2 1024-bit modulus
-
Group-14 2048-bit modulus
-
Group-15 3072-bit modulus
-
Group-16 4096-bit modulus
-
None: disable PFS
|