Configure Surelink Active Recovery For Ipsec - Digi IX40 User Manual

Table of Contents

Advertisement

Virtual Private Networks (VPN)
backup_ipsec_tunnel
Optional: yes
Current value:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover
b. Set the primary IPsec tunnel:
(config vpn ipsec tunnel backup_ipsec_tunnel)> ipsec_failover primary_ipsec_tunnel
(config vpn ipsec tunnel backup_ipsec_tunnel)>

Configure SureLink active recovery for IPsec

You can configure the IX40 device to regularly probe IPsec tunnels to determine if the connection has
failed and take remedial action.
You can also configure the IPsec tunnel to fail over to a backup tunnel. See
further information.
Required configuration items
n
A valid IPsec configuration. See
n
Enable IPsec SureLink.
n
The behavior of the IX40 device upon IPsec failure: either
Restart the IPsec interface
l
Reboot the device.
l
Additional configuration items
n
The interval between connectivity tests.
n
Whether the interface should be considered to have failed if one of the test targets fails, or all
of the test targets fail.
n
The number of probe failures before the IPsec connection is considered to have failed.
n
The amount of time that the device should wait for a response to a probe failures before
considering it to have failed.
To configure the IX40 device to regularly probe the IPsec connection:
É
Web
1. Log into Digi Remote Manager, or log into the local Web UI as a user with full Admin access
rights.
2. Access the device configuration:
Remote Manager:
a. Locate your device as described in
device.
b. Click the Device ID.
c. Click Settings.
IX40 User Guide
Configure an IPsec tunnel
Use Digi Remote Manager to view and manage your
Configure IPsec failover
for configuration instructions.
IPsec
for
385

Advertisement

Table of Contents
loading

Table of Contents