Unified Services Router
CLI Reference Guide
71
Sl No
Command Name
Description
Type and Description
31
auto_phase1_key_l
ength
BLOWFISH and CAST128 are variable
length algorithms, and so the key length
field is required when using either of
these encryption types. For
BLOWFISH, the Key Length must be
between 40 and 448 and it must be a
multiple of 8. For CAST128, the Key
Length must be between 40 and 128
and it must be a multiple of 8
Unsigned integer
32
auto_phase1_auth_
algorithm
Specify the authentication algorithm for
the VPN header. There are many
algorithms
Specify the authentication
algorithm for the VPN header.
Algorithms supported by this
router:
MD5/SHA-1/SHA2-256/SHA2-
384/SHA2-512)
33
auto_phase1_auth_
method
Select Pre-shared key for a simple
password based key. Selecting RSA-
Signature will disable the pre-shared
key text box and uses the Active Self
Certificate uploaded in the Certificates
page. In that case, a certificate must be
configureD
Pre-shared key/RSA Signature
(Pre-shared-Key/RSA-Signature)
34
auto_phase1_pre_s
hared_key
alpha-numeric key to be shared with
IKE peer
String,
alpha-numeric key to be shared
with IKE peer
35
auto_phase1_dh_gr
oup
The Diffie-Hellman algorithm is used
when exchanging keys. The DH Group
sets the strength of the algorithm in
bits.
(None/Group1/Group2/Group5/Gro
up14/Group15/Group16/Group17/
Group18)
36
auto_phase1_sa_li
fetime
the interval after which the Security
Association becomes invalid.
Unsigned integer,
37
auto_phase1_enabl
e_dead_peer_detec
tion
Dead Peer Detection is used to detect
whether the Peer is alive or not. If peer
is detected as Dead, it deletes the IPs
Boolean (Y/N)
38
auto_phase1_detec
tion_period
Detection Period is the interval between
consecutive DPD R-U-THERE
messages. DPD R-U-THERE
messages are sent only when
Unsigned integer,
Detection period interval
39
auto_phase1_recon
nect_failure_coun
t
Maximum number of DPD failures
allowed before tearing down the
connection.
Unsigned integer,
Dpd failure count
40
auto_phase1_exten
ded_authenticatio
n
Rather than configuring a unique VPN
policy for each user, you can enable the
VPN gateway router to authenticate
users from a stored list of user
accounts or with an external
authentication server such as a
RADIUS server. When connecting
many VPN clients to a VPN gateway
router, XAUTH allows authentication of
users with methods in addition to the
Extebded Authentication
(NONE/IPSec Host/Edge Device)