• Used if BGP is not supported by VPN

Customer gateway devices with static routing must

  • Launch IKE security association by pre-shared keys.
  • Create  IPsec Security Associations but only in Tunnel mode
  • Uses AES 128/256-bit encryption
  • Uses SHA-1/ SHA-2 hash
  • Use DH Perfect Forward Secrecy in “Group 2” mode
  • Before encryption , packet fragmentation is done

Single Site-to-Site VPN Connections

 

Menu