Step 6 | In the Edit Crypto Maps dialog box, configure these parameters:
-
In IKEv2 IPsec Proposals, click + and choose the transform sets to define how to secure tunnel traffic with authentication and encryption.
-
Check the Enable Reverse Route Injection check box to automatically insert static routes into the routing process for networks and hosts protected by a remote endpoint.
-
Check the Enable Client Services check box and specify the port number.
The Client Services server provides HTTPS (SSL) access, enabling Secure Client Downloader to receive software upgrades, profiles, localization and customization files, and other required files. If you enable this option, specify the client services port number. If disabled, users cannot download any files required by Secure Client.
Note |
You can use the same port as SSL VPN running on the same device. Even if SSL VPN is configured, you must enable this option to allow file downloads over SSL for IPsec-IKEv2 clients.
|
-
Check the Enable Perfect Forward Secrecy check box.
Use Perfect Forward Secrecy (PFS) to generate a unique session key for each encrypted exchange, protecting recorded exchanges from decryption even if endpoint keys are compromised. If enabled, choose a Diffie-Hellman key derivation algorithm for generating the PFS session key from the Modulus Group list.
-
From the Modulus group drop-down list, choose a modulus group.
The modulus group specifies the Diffie-Hellman group used to derive a shared secret between two IPsec peers without transmitting it. A larger modulus provides stronger security but requires more processing time. Both peers must use a matching modulus group. Choose a modulus group to allow in the remote access VPN configuration:
-
In the Lifetime Duration field, enter the lifetime of the security association (SA), in seconds.
The range is 120 to 2147483647 seconds. The default is 28800 seconds.
When the lifetime is exceeded, the SA expires and must be renegotiated between the two peers. Shorter lifetimes improve IKE negotiation security, while longer lifetimes allow future IPsec SAs to be established more quickly.
-
In the Lifetime Size (kbytes) field, enter the volume of traffic (in kilobytes) allowed between IPsec peers before the SA expires.
The range is 10 to 2147483647 kilobytes. The default is 4,608,000 kilobytes. If you do not specify a value, the SA allows unlimited data.
-
In ESPv3 Settings, configure these parameters:
-
Check the Validate incoming ICMP error messages check box to validate ICMP error messages received through an IPsec tunnel and destined for a host in the private network.
-
Check the Enable 'Do Not Fragment' Policy check box to define how the IPsec subsystem handles large packets with the do-not-fragment (DF) bit set in the IP header. From the Policy drop-down list, choose one of these options:
-
Check the Enable Traffic Flow Confidentiality (TFC) Packets check box to send dummy TFC packets that mask the traffic profile traversing the tunnel. Configure the Burst, Payload Size, and Timeout parameters to generate random-length packets at random intervals across the specified SA.
Note |
Enabling TFC packets prevents the VPN tunnel from being idle, which may cause the VPN idle timeout configured in the group policy to not work as expected.
|
-
Click OK.
|