IPsec (legacy)
IPsec (legacy) is a retired remote access VPN and isn't supported in SFOS 22.0 MR1 and later.
You can't upgrade to SFOS 22.0 MR1 and later if the firewall contains the legacy remote access IPsec configuration. You must delete the configuration, then upgrade.
You can restore backups and import configurations that contain the legacy remote access IPsec configuration, but this legacy configuration isn't migrated.
Tip
We recommend that you configure remote access connections using one of the following options:
- IPsec: See Remote access IPsec overview.
- SSL VPN: See Remote access SSL VPN overview.
Existing legacy connections
- To establish a remote connection using this option, remote users must have a third-party VPN client.
- Go to the connection you configured, and download the
.tarfile. Extract the.tgbfile, and share it with users. - Users must import it to the VPN client on their endpoint devices.