

Secure IKEv2 EAP user authentication (EAP-SIM, EAP-AKA, EAP-TLS, EAP-TTLS, EAP-PEAP, EAP-MSCHAPv2, etc.).Virtual IP address pool managed by IKE daemon or SQL database.XAUTH server and client functionality on top of IKEv1 Main Mode authentication.Static virtual IPs and IKEv1 ModeConfig pull and push modes.Dead Peer Detection (DPD, RFC 3706) takes care of dangling tunnels.Support of IKEv2 message fragmentation ( RFC 7383) to avoid issues with IP fragmentation.NAT-Traversal via UDP encapsulation and port floating ( RFC 3947).Automatic insertion and deletion of IPsec-policy-based firewall rules.

