Enabling DR mode on all peers
Verifying whether the entire configuration is DR compliant
To check whether the configuration is indeed fully compatible with DR mode, and to prevent the VPN policy from being disabled in the event of an anomaly, apply the following procedure to firewalls in SNS version 5.0 and higher:
- Go to System > Configuration > CLI console.
- Run CONFIG IPSEC CHECK index=<policy_idx> DRcompliant=1 command where <policy_idx> is the IPsec policy number (example: index=1 when IPsec policy number is 01).
Answer is OK when the configuration is compliant with DR mode.
Enabling DR mode
On the firewall in SNS version 5.0 or higher:
- Go to Configuration > System > Configuration > General configuration tab.
- In the Cryptographic settings section, select the Enable "Diffusion Restreinte" (DR) mode version 2020 checkbox.
- Restart the firewall to apply the activation of DR mode.
- Activate DR mode on each gateway peer
- After the firewall has restarted, check in the IPsec tunnel monitoring module whether all tunnels have been set up.