如果以下字段在两个防火墙之间不匹配,VPN 连接是否会受到影响?如果不是,则两侧的哪些元素必须相同以确保连通性。请记住,前 4 个是全局设置,最后一个(sla 监视器)是每个连接的配置。
crypto ipsec df-bit clear-df outside
crypto ipsec security-association replay window-size 128
crypto ipsec fragmentation before-encryption outside
sysopt connection tcpmss 1387
sla monitor 1
type echo protocol ipIcmpEcho x.x.x.x interface outside
frequency 5
exit