Articles included in this section:
Sophos XG V19+ ikev2 (dynamic)
SonicWall 6.5.4+ ikev2 (static)
SonicWall 6.5.4+ ikev2 (dynamic)
SonicWall 7.0.1+ ikev2 (static)
SonicWall 7.0.1+ ikev2 (dynamic)
FortiOS 6.4.4 > ikev2 (static)
FortiOS 6.4.4 > ikev2 (dynamic)
Security settings included in the files represent only the minimum requirements defined by AWS.
All supported security options can be found in the AWS documentation:
Configure tunnel options for AWS Site-to-Site VPN - AWS Site-to-Site VPN
The device must be configured in failover mode, ensuring that only one tunnel per VPN is active at any given time. Otherwise, there is a risk of asymmetric routing and resulting packet loss.
Below is a summary of the main AWS-side security settings that the customer can use in their configuration: