IPsec Configuration

You can configure an IPsec tunnel to transmit secure IP packets.

The following steps are required to configure IPsec for use in Common Criteria mode:

  • Configure an IKEv2 proposal and policy.
  • Configure an IKEv2 authentication proposal. The authentication proposal may be based on either a pre-shared key or on X.509 certification.
    • In Common Criteria mode, there is no default value for a pre-shared key. You must specify the preshared key.
    • If you use X.509 certification, you must also configure PKI. PKI can be configured for either automatic or manual enrollment.
  • Configure the IKEv2 profile.
  • Configure the IPsec profile.
  • Configure the IPsec tunnel and apply the IPsec profile.