SonicOS/X 7 IPSec VPN

Configuring Settings on the Advanced Tab

The Advanced tabs for IPv4 and IPv6 are similar, but some options are available only for one version or the other, as shown in Advanced Settings: Option Availability. Options also change depending on the authentication method selected.

Advanced Settings: Option Availability
Option IP Version
IPv4 IPv6
Enable Keep Alive Supported Supported
Suppress automatic Access Rules creation for VPN Policy Supported
Disable IPsec Anti-Replay Supported Supported
Enable Windows Networking (NetBIOS) Broadcast Supported
Enable Multicast Supported
Display Suite B Compliant Algorithms Only Supported Supported
Apply NAT Policies Supported
Using Primary IP Address Supported
Specify the local gateway IP address Supported
Preempt Secondary Gateway Supported Supported
Primary Gateway Detection Interval (seconds) Supported Supported
Do not send trigger packet during IKE SA negotiation Supported Supported
Accept Hash & URL Certificate Type Supported Supported
Send Hash & URL Certificate Type Supported Supported

Because an interface might have multiple IPv6 addresses, sometimes the local address of the tunnel might vary periodically. If a user needs a consistent IP address, select either the Using Primary IP Address or Specify the local gateway IP address option, or configure the VPN policy to be bound to an interface instead of a Zone. With Specify the local gateway IP address, specify the address manually. The address must be one of the IPv6 addresses for that interface.

IPv6+Add VPN Policy: Advanced

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden