A VPN that connects branch offices, worldwide partners, remote clients, and other environments, can reach hundreds or thousands of peers. A VPN on this scale brings new challenges. For example, when a new peer is deployed in production, you must define the peer and configure the environment again. Every time a new peer is deployed, you must Install Policy on all the Security Gateways.
The Large Scale VPN (LSV) feature addresses these challenges to deploy more easily and quickly. LSV is supported in R77.30 and higher.
To configure Large Scale VPN:
A CA can sign for only one LSV profile.
The LSV Profile is under Network Objects > Interoperable Devices.
Open SmartDashboard > IPsec VPN > Communities. Double-click the community to which you added the LSV profile, and make sure it is listed with the gateways.
You can monitor LSV peers on a Security Gateway with the vpn lsv
command.
vpn
lsv
********** Select Option **********
(1) List all LSV peers
(2) Show LSV peer's details
(3) Remove an LSV peer
(4) Remove all LSV peers
(Q) Quit
************
*******************************
You can also monitor LSV tunnels with SmartView Monitor.