[Contents] [Prev] [Next] [Index] [Report an Error]

Dynamic IPSec Subscriber Recognition

The E-series router expects to receive the Xauth vendor ID from the remote peer for dynamic interface instantiation. The expected Xauth vendor ID is 0x09002689DFD6B712.

Note: The E-series router does not initiate connections to new subscribers. Acceptable vendor IDs are global to the router and not user-configurable.

Phase 2 SAs intended for static tunnels and those intended for dynamic subscribers do not share the same phase 1 SA. This means that dynamic phase 1 SAs are only used to negotiate dynamic phase 2 SAs. Conversely, phase 1 SAs that are not recognized as dynamic are used only to negotiate phase 2 SA static tunnels.


[Contents] [Prev] [Next] [Index] [Report an Error]