![D-Link DSR-250 Cli Reference Manual Download Page 75](http://html1.mh-extra.com/html/d-link/dsr-250/dsr-250_cli-reference-manual_3850933075.webp)
Unified Services Router
CLI Reference Guide
73
Sl No
Command Name
Description
Type and Description
lifetime
54
auto_phase2_encry
ption_algorithm
The algorithm used to encrypt the data
vpn encryption algorithm
(None/DES/3DES/AES-128/AES-
192/AES-256/AES-CCM/AES-
GCM//TWOFISH(128/192/256)/
BLOWFISH/CAST128)
55
auto_phase2_key_l
ength
BLOWFISH and CAST128 are variable
length algorithms, and so the key length
field is required when using either of
these encryption types. For
BLOWFISH, the Key Length must be
between 40 and 448 and it must be a
multiple of 8. For CAST128, the Key
Length must be between 40 and 128
and it must be a multiple of 8.
Unsigned integer
56
auto_phase2_authe
ntication_algorit
hm
Algorithm used to verify the integrity of
the data.
vpn authentication algorithm
(MD5/SHA-1/SHA2-256/SHA2-
384/SHA2-512)
57
auto_phase2_enabl
e_pfskeygroup
Enable Perfect Forward Secrecy (PFS)
to improve security. While slower, this
protocol helps to prevent
eavesdroppers by ensuring that a
Diffie-Hellman exchange is performed
for every phase-2 negotiation.
PFSKeyGroup enable Boolean
(Y/N)
58
auto_phase2_dh_gr
oup
The Diffie-Hellman algorithm is used
when exchanging keys. The DH Group
sets the strength of the algorithm in
bits.
vpn Diffie-Hellman (DH) Groups
(None/Group1/Group2/Group5
Group14/Group15/Group16/Group
17/Group18)
59
save
Save vpn policy configuration changes.
60
cancel
Roll back vpn policy configuration
changes.
61
exit
Save vpn policy configuration changes
and exit current mode.
12.5 vpn ipsec policy disable <name>
Sl No
Command Name
Description
Type and Description
1
name
Name of vpn policy to be disabled
Unsigned integer,
Policy name
12.6 vpn ipsec policy enable <name>
Sl No
Command Name
Description
Type and Description
1
name
Name of vpn policy to be enabled
Unsigned integer,
Policy name