|
Tunnel Type
|
Umbrella: (Read only) ipsec
Zscaler: Click ipsec or gre .
Generic: Click ipsec or gre .
|
|
Interface Name (1..255)
|
Name of the interface.
|
|
Description
|
Description for the interface.
|
|
Tracker
|
By default, a tracker is attached to monitor the health of tunnels.
|
|
Tunnel Source Interface
|
Name of the source interface of the tunnel. This interface should be an egress interface and is typically the internet-facing
interface.
|
|
Source Public IP
|
(Automatic GRE tunnels to Zscaler only)
Public IP address of the tunnel source interface that is required to create the GRE tunnel to Zscaler.
Default: Auto
We recommend that you use the default configuration. With the default configuration, the Cisco IOS XE SD-WAN device finds
the public IP address assigned to the tunnel source interface using a DNS query. If the DNS query fails, the device notifies
Cisco SD-WAN Manager of the failure. Enter the public IP address only if the DNS query fails.
|
|
Data-Center
|
For a primary data center, click Primary , or for a secondary data center, click Secondary . Tunnels to the primary data center serve as active tunnels, and tunnels to the secondary data center serve as back-up tunnels.
|
|
Tunnel Destination IP Address/FQDN
|
(Manual tunnels only)
The IP address of the SIG provider endpoint. The configuration of FQDN for Tunnel Destination IP address is not supported.
|
|
Preshared Key
|
(Manual tunnels only)
This field is displayed only if you choose ipsec as the Tunnel Type .
Enter the password to use with the preshared key.
|
|
Advanced Options
|
|
Shutdown
|
Click No to enable the interface; click Yes to disable.
Default: No
|
|
IP MTU
|
Specify the maximum MTU size of packets on the interface.
Range: 576 to 2000 bytes
Default: 1400 bytes
|
|
TCP MSS
|
Specify the maximum segment size (MSS) of TPC SYN packets. By default, the MSS is dynamically adjusted based on the interface
or tunnel MTU such that TCP SYN packets are never fragmented.
Range: 500 to 1460 bytes
Default: None
|
|
DPD Interval
|
Specify the interval for IKE to send Hello packets on the connection.
Range: 10 to 3600 seconds
Default: 10
|
|
DPD Retries
|
Specify the number of seconds between DPD retry messages if the DPD retry message is missed by the peer.
After one DPD message is missed by the peer, the router changes the state and sends a DPD retry message at a faster retry
interval, which is the number of seconds between DPD retries if the DPD message is missed by the peer. The default DPD retry
message is sent every 2 seconds. Five DPD retry messages can be missed before the tunnel is marked as down.
Range: 2 to 60 seconds
Default: 3
|
|
IKE
|
|
IKE Rekey Interval
|
Specify the interval for refreshing IKE keys.
Range: 300 to 86400 seconds (1 hour to 14 days)
Default: 14400 seconds
|
|
IKE Cipher Suite
|
Specify the type of authentication and encryption to use during IKE key exchange.
Choose one of the following:
-
AES 256 CBC SHA1
-
AES 256 CBC SHA2
-
AES 128 CBC SHA1
-
AES 128 CBC SHA2
The IPsec Cipher Suite defaults vary by the type of the SIG:
-
Umbrella: AES 256 GCM
-
Zscaler: None
-
Generic: NULL SHA 512
|
|
IKE Diffie-Hellman Group
|
Specify the Diffie-Hellman group to use in IKE key exchange, whether IKEv1 or IKEv2.
-
2 1024-bit modulus
-
14 2048-bit modulus
-
15 3072-bit modulus
-
16 4096-bit modulus
The IKE group defaults vary by the type of the SIG:
-
Umbrella: 14 2048-bit modulus
-
Zscaler: 2 1024-bit modulus
-
Generic: 16 4096-bit modulus
|
|
IPSec
|
|
IPsec Rekey Interval
|
Specify the interval for refreshing IPsec keys.
Range: 300 to 1209600 seconds (1 hour to 14 days)
Default: 3600 seconds
|
|
IPsec Replay Window
|
Specify the replay window size for the IPsec tunnel.
Options: 64, 128, 256, 512, 1024, 2048, 4096.
Default: 512
|
|
IPsec Cipher Suite
|
Specify the authentication and encryption to use on the IPsec tunnel.
Options:
-
AES 256 CBC SHA1
-
AES 256 CBC SHA 384
-
AES 256 CBC SHA 256
-
AES 256 CBC SHA 512
-
AES 256 GCM
-
NULL SHA1
-
NULL SHA 384
-
NULL SHA 256
-
NULL SHA 512
Default: AES 256 GCM
|
|
Perfect Forward Secrecy
|
Specify the PFS settings to use on the IPsec tunnel. Choose one of the following Diffie-Hellman prime modulus groups:
-
Group-2 1024-bit modulus
-
Group-14 2048-bit modulus
-
Group-15 3072-bit modulus
-
Group-16 4096-bit modulus
-
None: disable PFS
The Perfect Forward Secrecy defaults vary by the type of the SIG:
-
Umbrella: None
-
Zscaler: None
-
Generic: Group 16
|