AlterPath ACS Command Reference Guide
145
Network
Parameters are optional unless marked required; a parameter required for manual keying
need not be included for a connection which will use only automatic keying, and vice
versa.
Conn parameters: General.
The following parameters are relevant to both automatic
and manual keying. Unless otherwise noted, for a connection to work, in general it is
necessary for the two ends to agree exactly on the values of these parameters. The two
ends can be defined as Left or Local, and Right or Remote.
•
type: The type of the connection. Currently the accepted values are: tunnel (the
default) signifying a host-to-host, host-to-subnet, or subnet-to-subnet tunnel;
transport, signifying host-to-host transport mode; and passthrough (supported only
for manual keying), signifying that no IPsec processing should be done at all.
•
left (local) and right (remote) IP: The IP address of the participant's network
interface. If it is the magic value %defaultroute, and interfaces=%defaultroute is
used in the config setup section, left will be filled in automatically with the local
address of the default-route interface (as determined at IPsec startup time). This
also overrides any value supplied for leftnexthop. (Either left or right may be
%defaultroute, but not both.) The magic value %any signifies an address to be
filled in (by automatic keying) during negotiation; the magic value %opportunistic
signifies that both left and leftnexthop are to be filled in (by automatic keying)
from DNS data for left's client.
•
left(local) and right (remote) subnet: Private subnet behind the left and right
participants, expressed as network/netmask.
•
left(local) and right (remote) nexthop: NextHop gateway IP address for the left and
right participant connection to the public network.
•
left (local) and right (remote) updown script: What updown script to run to adjust
routing and/or firewalling when the status of the connection changes. The path to
the default updown script on ACS is /usr/local/lib/ipsec/_updown
Conn parameters: Automatic Keying.
The following parameters are relevant only to
automatic keying, and are ignored in manual keying. Unless otherwise noted, for a
connection to work, in general it is necessary for the two ends to agree exactly on the
values of these parameters.
•
auto: What operation, if any, should be done automatically at IPsec startup;
currently- accepted values are add (signifying an ipsec auto --add), route
(signifying that plus an ipsec auto --route), start (signifying that plus an ipsec auto
--up), and ignore (also the default) (signifying no automatic startup operation).
This parameter is ignored unless the plutoload or plutostart configuration
parameter is set suitably; see the config setup discussion below.
•
auth: Whether authentication should be done as part of ESP encryption, or
separately using the AH protocol, acceptable values are esp (the default) and ah.
•
authby: How the two security gateways should authenticate each other. Acceptable
values are secret for shared secrets (the default) and rsasig for RSA digital
signatures.
Содержание AlterPath ACS
Страница 16: ...xvi Table of Contents...
Страница 29: ...13 This page has been left intentionally blank...
Страница 30: ...14 Preface...
Страница 68: ...52 Device Access...
Страница 86: ...70 Authentication Step 5 Saving changes To save the configuration run the command saveconf...
Страница 96: ...80 Authentication Save the configuration to flash 2 cli config savetoflash...
Страница 114: ...98 Authentication...
Страница 204: ...188 Administration To exit the CLI mode and return to ACS s shell issue the command cli quit...
Страница 268: ...252 Power Management with AlterPath PM Integration...
Страница 304: ...288 PCMCIA Cards Integration...
Страница 338: ...322 Profile Configuration...
Страница 364: ...348 Additional Features and Applications...
Страница 376: ...360 Appendix A New User Background Information...
Страница 406: ...390 Appendix C Cabling and Hardware Information This page has been left intentionally blank...
Страница 418: ...402 List of Tables...
Страница 420: ...404 List of Figures...