Understand how to connect a Cisco ISR-G2, ISR4K, or CSR router through both primary and secondary IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnels to Cisco Secure Access.
Follow the steps in this guide to connect a Cisco ISR-G2, ISR4K, or CSR router through both primary and secondary IPsec (Internet Protocol Security) IKEv2 (Internet Key Exchange, version 2) tunnels to Cisco Secure Access.
Before you begin
The following prerequisites must be met for the tunnels to work successfully.
-
A valid Cisco Secure Access account.
-
A Cisco Secure Access organization ID. For more information, see Find Your Organization ID.
-
A router (ISR-G2, ISR4K, or CSR) with a security K9 license to establish an IPsec tunnel.
An HSEC license is required to get high-throughput internet bandwidth for SLVPN tunnel setup.
-
A Secure Access data center IP address to use when creating the IPsec tunnel. In the sample commands,
<sse_dc_ip>refers to this IP address. We recommend choosing the IP address based on the data center located closest to your device. -
Open UDP ports 500 and 4500 before connecting to the tunnel.
Cisco router (ISR-G2, ISR4K, or CSR) devices do not require public static IPv4 addresses configured on the interface that connects to the public internet and Secure Access. You can deploy these devices behind a NAT device. This is because we can specify a text as its IKE ID. This ID in combination with the PSK is used to successfully authenticate the Cisco router (ISR-G2, ISR4K, or CSR) devices with Secure Access.
Text as an IKE ID also allows multiple tunnels to be established from the same Cisco router device with a single IP address. This provides an opportunity to increase bandwidth by increasing the number of tunnels.