mirror of
https://github.com/vyos/vyos-documentation.git
synced 2025-10-26 08:41:46 +01:00
Change IPSec ESP mode from tunnel to transport to fix issue when Spokes behind a NAT
This commit is contained in:
parent
7710c7e959
commit
904bc5cbae
@ -199,7 +199,7 @@ Hub
|
||||
|
||||
set vpn ipsec esp-group ESP-HUB compression 'disable'
|
||||
set vpn ipsec esp-group ESP-HUB lifetime '1800'
|
||||
set vpn ipsec esp-group ESP-HUB mode 'tunnel'
|
||||
set vpn ipsec esp-group ESP-HUB mode 'transport'
|
||||
set vpn ipsec esp-group ESP-HUB pfs 'dh-group2'
|
||||
set vpn ipsec esp-group ESP-HUB proposal 1 encryption 'aes256'
|
||||
set vpn ipsec esp-group ESP-HUB proposal 1 hash 'sha1'
|
||||
@ -307,7 +307,7 @@ VyOS can also run in DMVPN spoke mode.
|
||||
|
||||
set vpn ipsec esp-group ESP-HUB compression 'disable'
|
||||
set vpn ipsec esp-group ESP-HUB lifetime '1800'
|
||||
set vpn ipsec esp-group ESP-HUB mode 'tunnel'
|
||||
set vpn ipsec esp-group ESP-HUB mode 'transport'
|
||||
set vpn ipsec esp-group ESP-HUB pfs 'dh-group2'
|
||||
set vpn ipsec esp-group ESP-HUB proposal 1 encryption 'aes256'
|
||||
set vpn ipsec esp-group ESP-HUB proposal 1 hash 'sha1'
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user