Chapter14 Enhanced Easy VP N
14-10
Cisco Router and Security Device Manager 2.5 User’s Guide
OL-4015-12
group5—The 1536-bit Diffie-Hellman prime modulus group is used to
encrypt the PFS request.
Create Virtual Tunnel Interface
Enter the information for a virtual tunnel interface in this dialog.

Interface Type

Choose default, or tunnel as the interface type. If you are editing a virtual tunnel
interface, the configured value is displayed and the field is read only.

Configure the interface IP address

The IP address of the virtual tunnel interface can be unnumbered to another
interface, or it can have no IP address. Choose IP Unnumbered and choose an
interface name in the Unnumbered to field, or choose No IP address.
Tunnel Mode
Cisco SDM currently supports the IPSec-IPv4 tunnel mode and it is selected.

Select Zone

This field appears when the router runs a Cisco IOS image that supports
Zone-Policy Based Firewall (ZPF), and a zone has been configured on the router.
If you want this virtual tunnel interface to be a zone member, click the button to
the right of this field. Click Select a Zone and select the zone that you want the
interface to be a member of, or click Create a Zone to create a new zone for this
interface.
Note It is not required that the virtual tunnel interface be a member of a zone. However,
the router does not forward traffic between zone-member interfaces and non
zone-member interfaces.