Chapter 28 IPSec VPN
ZyWALL / USG (ZLD) CLI Reference Guide
196
28.2.9 IPv6 IPSec SA Commands
This table lists the commands for IPv6 IPSec SAs.
[no] eap type {server
auth_method
user-id
{name|any}| client name
username {password
PASSWORD| encrypted-
password PASSWORD}
Enables extended authentication and specifies whether the ZyWALL/ USG is the
server or client. If the ZyWALL / USG is the server, it also specifies the AAA
authentication method (aaa authentication profile_name); if the ZyWALL / USG is
the client, it also specifies the username and password to provide to the remote
IPSec router. The no command disables extended authentication.
•
username: You can use alphanumeric characters, underscores (_), and dashes (-
), and it can be up to 31 characters long.
•
password: You can use most printable ASCII characters. You cannot use square
brackets [ ], double quotation marks (“), question marks (?), tabs or spaces. It
can be up to 31 characters long.
ikev2 policy rename
policy_name policy_name
Renames the specified IKEv2 SA (first policy_name) to the specified name (second
policy_name).
Table 108
sa Commands: IPv6 IKEv2 (continued)
COMMAND
DESCRIPTION
Table 109
crypto Commands: IPv6 IPSec SAs
COMMAND
DESCRIPTION
show crypto map6 [
map_name
]
Shows the specified IPSec SA or all IPSec SAs.
crypto map6 dial
map_name
Dials the specified IPSec SA manually. This command does not
work for IPSec SAs using manual keys or for IPSec SAs where the
remote gateway address is 0.0.0.0.
[no] crypto map
map_name
Creates the specified IPSec SA if necessary and enters sub-
command mode. The
no
command deletes the specified IPSec SA.
crypto map rename
map_name map_name
Renames the specified IPSec SA (first
map_name
) to the specified
name (second
map_name
).
crypto map
map_name
activate
deactivate
Activates or deactivates the specified IPSec SA.
adjust-mss {auto | <200..1500>}
Set a specific number of bytes for the Maximum Segment Size
(MSS) meaning the largest amount of data in a single TCP
segment or IP datagram for this VPN connection or use
auto
to
have the ZyWALL automatically set it.
ipsec-isakmp
policy_name
Specifies the IKE SA for this IPSec SA and disables manual key.
encapsulation {tunnel | transport}
Sets the encapsulation mode.
transform-set
crypto_algo_esp
[
crypto_algo_esp
[
crypto_algo_esp
]]
Sets the active protocol to ESP and sets the encryption and
authentication algorithms for each proposal.
crypto_algo_esp
: esp-null-md5 | esp-null-sha | esp-null-sha256
| esp-null-sha512 | esp-des-md5 | esp-des-sha | esp-des-sha256
| esp-des-sha512 | esp-3des-md5 | esp-3des-sha | esp-3des-
sha256 | esp-3des-sha512 | esp-aes128-md5 | esp-aes128-sha |
esp-aes128-sha256 | esp-aes128-sha512 | esp-aes192-md5 |
esp-aes192-sha | esp-aes192-sha256 | esp-aes192-sha512 | esp-
aes256-md5 | esp-aes256-sha | esp-aes256-sha256 | esp-
aes256-sha512
transform-set
crypto_algo_ah
[
crypto_algo_ah
[
crypto_algo_ah
]]
Sets the active protocol to AH and sets the encryption and
authentication algorithms for each proposal.
crypto_algo_ah
: ah-md5 | ah-sha | ah-sha256 | ah-sha512
Summary of Contents for ZyWALL USG Series
Page 19: ...19 PART I Introduction ...
Page 20: ...20 ...
Page 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Page 39: ...39 PART II Reference ...
Page 40: ...40 ...
Page 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Page 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Page 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Page 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Page 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Page 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Page 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Page 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Page 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Page 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Page 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Page 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Page 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Page 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Page 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Page 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Page 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Page 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Page 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Page 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Page 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Page 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Page 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Page 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Page 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...