ModifyVpnTunnelOptionsSpecification
The Amazon Web Services Site-to-Site VPN tunnel options to modify.
Types
Properties
The action to take after DPD timeout occurs. Specify restart
to restart the IKE initiation. Specify clear
to end the IKE session.
The number of seconds after which a DPD timeout occurs. A DPD timeout of 40 seconds means that the VPN endpoint will consider the peer dead 30 seconds after the first failed keep-alive.
Turn on or off tunnel endpoint lifecycle control feature.
The IKE versions that are permitted for the VPN tunnel.
Options for logging VPN tunnel activity.
One or more Diffie-Hellman group numbers that are permitted for the VPN tunnel for phase 1 IKE negotiations.
One or more encryption algorithms that are permitted for the VPN tunnel for phase 1 IKE negotiations.
One or more integrity algorithms that are permitted for the VPN tunnel for phase 1 IKE negotiations.
The lifetime for phase 1 of the IKE negotiation, in seconds.
One or more Diffie-Hellman group numbers that are permitted for the VPN tunnel for phase 2 IKE negotiations.
One or more encryption algorithms that are permitted for the VPN tunnel for phase 2 IKE negotiations.
One or more integrity algorithms that are permitted for the VPN tunnel for phase 2 IKE negotiations.
The lifetime for phase 2 of the IKE negotiation, in seconds.
The pre-shared key (PSK) to establish initial authentication between the virtual private gateway and the customer gateway.
The percentage of the rekey window (determined by RekeyMarginTimeSeconds
) during which the rekey time is randomly selected.
The margin time, in seconds, before the phase 2 lifetime expires, during which the Amazon Web Services side of the VPN connection performs an IKE rekey. The exact time of the rekey is randomly selected based on the value for RekeyFuzzPercentage
.
The number of packets in an IKE replay window.
The action to take when the establishing the tunnel for the VPN connection. By default, your customer gateway device must initiate the IKE negotiation and bring up the tunnel. Specify start
for Amazon Web Services to initiate the IKE negotiation.
The range of inside IPv4 addresses for the tunnel. Any specified CIDR blocks must be unique across all VPN connections that use the same virtual private gateway.
The range of inside IPv6 addresses for the tunnel. Any specified CIDR blocks must be unique across all VPN connections that use the same transit gateway.