Describes Best Practices for Configuring Network Tunnels by Device in Cisco Secure Access. You can establish an IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnel from a network device deployed in your environment to Cisco Secure Access.
You can establish an IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnel from a network device deployed in your environment to Cisco Secure Access. IPsec tunnels created for Secure Access accept traffic on all ports and protocols with a throughput of 1 Gbps per tunnel.
High availability
You must deploy both a primary and a backup tunnel to ensure high availability. If you configure only a primary tunnel, you will experience interruption of service during regular maintenance windows or unplanned outages.
Higher throughput
If you require more than 1 Gbps of throughput, you can set up multiple tunnels in a network tunnel group and join them with Equal-Cost Multi-Path (ECMP) routing.