IPsec Source IP Address Per Tunnel Interface

Table 1. IPsec Source IP Address per tunnel product support

Feature

Product

Release introduced

Ability to configure a specific IPsec source IP per tunnel

5320 Series

Not Supported

5420 Series

Not Supported

5520 Series

Not Supported

5720 Series

Not Supported

7520 Series

Not Supported

7720 Series

Not Supported

VSP 4450 Series

Not Supported

VSP 4900 Series

Not Supported

VSP 7200 Series

Not Supported

VSP 7400 Series

Not Supported

VSP 8200 Series

Not Supported

VSP 8400 Series

Not Supported

VSP 8600 Series

Not Supported

XA1400 Series

VOSS 8.3.1

To deploy the XA1400 Series in an environment that includes more than one provider connection with IPsec, you require a source IP address for each IPsec tunnel.

When you connect to a broadband provider such as cable modem, DSL, or LTE, the only routable IP interface is the one that is assigned by the provider (either through DHCP or statically). As a result, the Internet can only route the assigned subnet. You cannot deploy a routing protocol between the branch device and the provider modem.

When you connect two different providers to a branch device, each provider uses a different subnet. The XA1400 Series must apply a different source IP address for each IPsec tunnel.

The following options are available to configure a specific source IP address for each IPsec tunnel: