![Comnet reliance RL1000GW Скачать руководство пользователя страница 152](http://html1.mh-extra.com/html/comnet/reliance-rl1000gw/reliance-rl1000gw_installation-and-operation-manual_2644386152.webp)
INS_RL1000GW_REV– 15 Jul 2016 PAGE 152
INSTALLATION AND OPERATION MANUAL
RL1000GW
TECH SUPPORT: 1.888.678.9427
IPsec Commands
Command
Description
rsA-signature import
Import the X.509 certificate file and key file to the application from a connected USB drive
or tftp /sftp servers.
These files are mandatory for IPSec to encrypt using X.509 certificates.
These files are not required if IPSec is used with preshared keys.
show rsA-signature list
Show the files available
IPsec
Enter the IPsec configuration mode
Enable | disable
Default is disable
rsa-signature activate
Activation of the available certificate and key files.
Crt-file ; name of the certificate file.
Key-file : name of the key file.
rsa-sig-name : user configurable name for the signature.
isakmp update
authentication-method
pre_shared_key : preshared keys will be used. (default)
Rsasig : X.509 certificates will be used.
dh-group
Diffie–Hellman key exchange Group. Relates to phase 1.
determines the strength of the key used in the key exchange process. The higher the group
number, the stronger the key and security increases.
Options :
none
modp768 (DH group 1)
modp1024 (default) (DH group 2)
modp1536 (DH group 3 and 5)
modp2048 (DH group 14)
modp3072 (DH group 15)
modp4096 (DH group 16)
modp6144 (DH group 17)
modp8192 (DH group 18)
pfs-group
Perfect Forward Secrecy type. Relates to phase 2.
determines the strength of the key used in the key exchange process. The higher the group
number, the stronger the key and security increases.
Options:
none
modp768
modp1024 (default)
modp1536
modp2048
modp3072
modp4096
modp6144
modp8192
dpd-delay
Dead Peer Discovery delay .defines the interval between following keep alive messages.
Permissible range : 0-120
(default is 5)
dpd-maxfail
Dead Peer Discovery max attempts to determine failure.
Permissible range :2-20
(default is 5)
dpd-retry
Dead Peer Discovery max retry attempts. A retry is initiated after a failure at “dpd-maxfail”.
Permissible range : 1-20
(default is 5)