Restrictions on using hot standby together with IPSec on the USG2000 and USG5000 series

Restrictions on using hot standby together with IPSec: 1. The device supports the interworking of IPSec and hot standby in active/standby mode but not in load balancing mode. 2. When hot standby runs together with IPSec, the upstream and downstream service interfaces of the active and standby devices must be Layer-3 interfaces. 3. When hot standby runs together with IPSec, the hot standby configuration and IPSec configuration are the same as they run alone. 4. The IPSec policy needs to be configured only on the active device. 5. If the local device is the initiator of an IPSec tunnel, set the local gateway IP address at phase 2 to the virtual IP address of the VRRP group.

Scroll to top