Home > Configuration—Common Objects > Network Configuration > Configure Layer 2 IPsec VPN Services > Configure Advanced Client Options | ![]() |
First, create a Layer 2 IPsec VPN service. For more information, see Configure Layer 2 IPsec VPN Services.
For Layer 2 IPsec VPN tunnels, all management servers (CAPWAP, Syslog, SNMP, NTP, RADIUS, Active Directory, and LDAP) should be reachable from the VPN client without tunneling by default. However, you might want to tunnel some or all management traffic from the VPN client to servers on the main network.

Note
Set the following options only when the servers are in a different subnet from that of the tunnel interface. When they are in the same subnet, tunneling is automatic. In addition, the IP address/host name objects for the following servers must have IP address definitions as opposed to host name definitions.The DPD and tunnel heartbeat settings control when to fail over from the primary to the secondary VPN server. The DPD messages verify the presence of an IKE peer, and AMRP (Advanced Mobility Routing Protocol) tunnel heartbeats verify communications through the GRE and VPN tunnel. The failure of either mechanism can trigger a failover.
After a heartbeat fails to elicit a response from the VPN server, the VPN client retries every second.
Copyright © 2026 Extreme Networks. All rights reserved. Published February 17, 2026.


