ZyXEL Confidential
340adq4c0
18/36
edit forwardip [ip]
set nat server server ip
edit protocol [protocol id]
set nat server protocol
service
irc [on|off]
turn on/off irc flag
resetport
reset all nat server table entries
incikeport
[on|off]
turn on/off increase ike port flag
IPSec Related Command
Home
Command
Description
ipsec
debug
<1|0>
turn on|off trace for IPsec debug information
route
lan
<on|off>
After a packet is IPSec processed and will be sent
to LAN side, this switch is to control if this
packet can be applied IPSec again.
Remark: Command available since 3.50(WA.3)
wan
<on|off>
After a packet is IPSec processed and will be sent
to WAN side, this switch is to control if this
packet can be applied IPSec again.
Remark: Command available since 3.50(WA.3)
show_runtime
sa
display runtime phase 1 and phase 2 SA
information
spd
When a dynamic rule accepts a request and a
tunnel is established, a runtime SPD is created
according to peer local IP address. This
command is to show these runtime SPD.
switch
<on|off>
As long as there exists one active IPSec rule, all
packets will run into IPSec process to check SPD.
This switch is to control if a packet should do
this. If it is turned on, even there exists active
IPSec rules, packets will not run IPSec process.
timer
chk_my_ip
<1~3600>
- Adjust timer to check if WAN IP in menu is
changed
- Interval is in seconds
-
Default
is
10
seconds
- 0 is not a valid value
chk_conn.
<0~255>
-
Adjust
auto-timer to check if any IPsec
connection has no traffic for certain period. If
yes, system will disconnect it.
- Interval is in minutes
-
Default
is
2
minuets
- 0 means never timeout
update_peer
<0~255>
- Adjust auto-timer to update IPSec rules which
use domain name as the secure gateway IP.
- Interval is in minutes
-
Default
is
30
minutes
-
0
means
never
update
Remark: Command available since 3.50(WA.3)
updatePeerIp
Force system to update IPSec rules which use
domain name as the secure gateway IP right
away.
Remark: Command available since 3.50(WA.3)
dial
<rule #>
Initiate IPSec rule <#> from ZyWALL box
Remark: Command available since 3.50(WA.3)