After the enterprise branch and its headquarters establish an IPSec tunnel, the IP address of the branch gateway interface to which an IPSec policy group is applied changes due to the link status change. For example, the branch gateway connects to the Internet through dial-up and establishes an IPSec tunnel with the headquarters. The headquarters gateway has an existing IPSec tunnel to protect IPSec packets exchanged between the headquarters gateway and branch gateway (original users). Because data flows of new users are the same, the branch gateway and headquarters gateway cannot reestablish an IPSec tunnel. After the local IP address of the IPSec tunnel on the branch gateway changes, the branch gateway (new users) and headquarters gateway cannot rapidly reestablish an IPSec tunnel to protect IPSec traffic exchanged between them.
You can configure the device to allow new users with the same traffic rule as original branch users to access the headquarters network so that the existing IPSec SAs can be rapidly aged and a new IPSec tunnel can be established.
The prerequisites are as follows:
The system view is displayed.
The device is configured to allow new users with the same traffic rule as original branch users to access the headquarters network.
By default, the device allows branch or other users to quickly access the headquarters network after their IP addresses are changed.
The ipsec remote traffic-identical accept command is only used to detect whether the same data flows exist in a CPU.