Configure remote access VPN IPsec and IKEv2 parameters

You can update the IKEv2 session settings, IKEv2 security association settings, IPsec settings, and NAT traversal settings.

Procedure


Step 1

Choose Secure Connections > Remote Access VPN.

Step 2

Click the edit icon next to the remote access VPN policy.

Step 3

Click the Advanced tab.

Step 4

In the left pane, click IPsec > IPsec/IKEv2 Parameters.

Step 5

In IKEv2 Session Settings, configure these parameters:

  • From the Identity Sent to Peers drop-down list, choose how peers identify themselves during IKE negotiations. You can choose one of these options:

    • Auto—Determines the IKE negotiation by connection type.

    • IP address—Uses the IP addresses of the hosts exchanging ISAKMP identity information.

    • Hostname—Uses the fully qualified domain name (FQDN) of the hosts exchanging ISAKMP identity information. This name comprises the hostname and the domain name.

  • Check the Enable Notification on Tunnel Disconnect check box to enable the device to send an IKE notification to the peer when an inbound packet does not match the traffic selectors for its SA. By default, this option is disabled.

  • Check the Do not allow device reboot until all sessions are terminated check box to ensure the device completes all active sessions before it restarts. By default, this option is disabled.

Step 6

In IKEv2 Security Association (SA) Settings, configure these parameters:

  • From the Cookie Challenge drop-down list, choose when to send cookie challenges to peers in response to SA initiation packets. This feature prevents DoS attacks. By default, the system uses cookie challenges when 50% of the available SAs are in negotiation. Choose one of these options:

    • Custom—In the Threshold to Challenge Incoming Cookies field, enter the percentage of in-negotiation SAs that triggers cookie challenges for future negotiations. The range is zero to 100%. The default is 50%.

    • Always—Sends cookie challenges to peer devices always.

    • Never—Disables cookie challenges to peer devices.

  • In the Number of SAs Allowed in Negotiation field, enter the maximum number of SAs permitted in negotiation at any time, in percentage. If you use this parameter with Cookie Challenge, configure the cookie challenge threshold lower than this limit. The default is 100%.

  • In the Maximum number of SAs Allowed field, enter the maximum number of allowed IKEv2 connections.

Step 7

In IPsec Settings, configure these parameters:

  • Check the Enable Fragmentation Before Encryption check box if your network includes NAT devices that do not support IP fragmentation.

  • Check the Path Maximum Transmission Unit Aging check box to reset the PMTU of an SA at regular intervals.

  • In the Value Reset Interval field, enter the interval, in minutes, at which the PMTU value of an SA is reset to its original value. The range is 10 to 30 minutes.

Step 8

In NAT Transparency Settings, configure these parameters:

  • Check the Enable IPsec over NAT-T check box to allow seamless communication between the peer Firewall Threat Defense devices when there are NAT devices between these devices.

    Note
    NAT-Traversal uses port 4500. Ensure that other services, such as NAT policy, do not use this port.
  • In the NAT Keepalive Interval field, enter the interval, in seconds, between the keepalive signals sent between the devices to indicate that the session is active. The range is 10 to 3600 seconds. The default is 20 seconds.

    The Firewall Threat Defense device transmits NAT traversal keepalive messages when an intermediate NAT device exists between the Firewall Threat Defense device and the endpoint.

Step 9

Click Save.