Limitations for remote access VPN

Review these limitations before you configure a remote access VPN.

  • Do not configure IPSec tunnels with null encryption on Firewall Threat Defense devices, as they are not supported.

  • Use IPsec-IKEv2 instead of SSL when implementing remote access VPN with ECMP, as SSL is not supported in ECMP environments.

  • Remote access VPN does not support clustering configurations.

  • Secure Client does not support TACACS, Kerberos Constrained Delegation (KCD) and RSA SecurID (SDI), and SDI authentication methods when connecting to a Firewall Threat Defense device.