Creating or modifying IPsec interfaces (VTI)

These interfaces make it possible to set up routed IPsec tunnels. The virtual IPsec interface acts as a traffic endpoint and all packets routed to this interface will then be encrypted. Such configurations may make it possible, for example, to make QoS traffic pass through a dedicated IPsec tunnel: high-priority traffic will then take a specific tunnel while other traffic will go through a second tunnel.

To create or modify a virtual IPsec interface, click on the IPsec interfaces (VTI) tab.

Button bar

Enter a filter This field makes it possible to search for an interface by entering a sequence of characters included in its name.
Add Adds a new interface. An added interface (sending of a command) is effective only if its fields Name, IP address and Network mask have been entered.
Delete Deletes one or several selected interfaces. Use the keys Ctrl/Shift + Delete to delete several interfaces.
Check usage Represented by the icon , this button indicates whether the selected interface is being used elsewhere in the configuration.
 
ApplyApplies the configuration of the IPsec interfaces.
CancelCancels the configuration of the IPsec interfaces.

Interactive features

Some operations listed in the taskbar can be performed by right-clicking on the table of virtual IPsec interfaces:

  • Add,
  • Delete,
  • Check usage.

Presentation of the table

The grid presents, in the form of columns, the information that is defined when creating a virtual IPsec interface:

Status

Status of the interfaces:

  • Enabled: Double-click to enable the created interface.
  • Disabled: The interface is not in operation. The line will be grayed out in order to reflect this.
Name (mandatory)Name the IPsec interface.

NOTE
Please refer to the section Allowed names to find out which characters are allowed and prohibited in various fields.

IPv4 address and mask (mandatory)

Enter the IP address/network mask pair that describes the virtual interface created.

The mask format can be decimal (e.g., 255.255.255.252) or CIDR (e.g., %30).

Since virtual IPsec interfaces are meant for setting up point-to-point tunnels, a network that allows assigning two addresses is sufficient in theory.

 

Protected

This column is hidden by default. If you wish to show it:

  1. Scroll over the column header,
  2. Click on the drop-down menu that appears to the right of the column header,
  3. Select Column > Protected.

When the column is shown, double-click on the corresponding cell to change the interface type:

  • Protected
  • Public
Comments (optional)Any text.