General Considerations when the Device is in the Common Criteria Administrative Mode
The following general considerations apply when the device is in the Common Criteria administrative mode (applies only to the VPNGW mode, and IPsec must be used for VPNGW).
- Use RADIUS/UDP over the IPsec tunnel configured for managing the device.
- IPsec stack is not available on the management port.
- Configure the VPN gateway separately since it requires logging into the device.
- Configure the VPN gateway NAT translation separately.
- VPN gateway allows Syslog to use IPsec instead of TLS.
- Extended IKEv2 and extended PKI logging needs to be enabled to log the entire contents of packets associated with establishing a session with an IPsec peer.
Note: You must copy the signature file before copying the corresponding image file; otherwise,
image validation fails.