The IPSec function is supported by all models.
By default, IPSec does not support weak security algorithms such as MD5, SHA1, DES, 3DES, DH-GROUP1, DH-GROUP2, and DH-GROUP5. To use these algorithms, you need to install the weak security algorithm component package (product_version_WEAKEA.mod). For details about the component package, see Dynamic Loading.
When a NAT device is deployed between IPSec peers, NAT traversal must be enabled and the security protocol must be ESP.
In AH encapsulation mode, the DF flag bit of the inner packet is inherited to the outer packet, and the FW combines it with the DF flag bit of the outer layer to calculate the checksum of the packet. If the peer end of the tunnel removes the DF flag bit from the outer packet and then calculates the checksum, the checksums on both ends of the tunnel are inconsistent. As a result, the interconnection fails. To prevent this, run the ipsec df-bit clear command to ensure that the checksums on both ends of the tunnel are consistent.
In dual-system hot backup scenarios, the local IP address of an IPSec tunnel cannot be configured as the peer IP address by using the remote-address command in the IKE peer view. Otherwise, the standby device cannot back up the IPSec tunnel information generated by hosts based on the IKE peer.