AlterPath ACS Command Reference Guide
147
Network
•
espauthkey: ESP authentication key.
•
espreplay_window: ESP replay-window setting. An integer from 0 to 64. Relevant
only if ESP authentication is being used.
•
ah: AH authentication algorithm to be used for the connection, e.g. hmac-md5-96.
Default is not to use AH.
•
ahkey: Required if ah is present. AH authentication key
•
ahreplay_window: AH replay-window setting. An integer from 0 to 64.
Config Section
At present, the only config section known to the IPsec software is the one named setup,
which contains information used when the software is being started. Here's an example:
Parameters are optional unless marked required. The currently-accepted parameter
names in a config setup section are:
•
interfaces: Required. Virtual and physical interfaces for IPsec to use: a single
virtual= physical pair, a quoted list of pairs separated by white space, or
%defaultroute, which means to find the interface d that the default route points to,
and then act as if the value was ipsec0=d.
•
forwardcontrol: Whether setup should turn IP forwarding on (if it's not already on)
as IPsec is started, and turn it off again (if it was off) as IPsec is stopped.
Acceptable values are yes and (the default) no.
•
klipsdebug: How much KLIPS debugging output should be logged. An empty
value, or the magic value none, means no debugging output (the default). The
magic value all means full output.
•
plutodebug: How much Pluto debugging output should be logged. An empty value,
or the magic value none, means no debugging output (the default). The magic
value all means full output.
•
dumpdir: In what directory should things started by setup (notably the Pluto
daemon) be allowed to dump core. The empty value (the default) means they are
not allowed to.
•
manualstart: Which manually-keyed connections to set up at startup (can be empty,
a name, or a quoted list of names separated by white space).
•
plutoload: Which connections (by name) to load into Pluto's internal database at
startup (can be empty, a name, or a quoted list of names separated by white space);
see ipsec_auto for details. Default is none. If the special value %search is used, all
connections with auto=add, auto=route, or auto=start are loaded.
config setup
interfaces="ipsec0=eth1 ipsec1=ppp0"
klipsdebug=none
plutodebug=all
manualstart=
plutoload="snta sntb sntc sntd"
plutostart=
File Description 4.5: part of the /etc/ipsec.conf file
Содержание AlterPath ACS
Страница 16: ...xvi Table of Contents...
Страница 29: ...13 This page has been left intentionally blank...
Страница 30: ...14 Preface...
Страница 68: ...52 Device Access...
Страница 86: ...70 Authentication Step 5 Saving changes To save the configuration run the command saveconf...
Страница 96: ...80 Authentication Save the configuration to flash 2 cli config savetoflash...
Страница 114: ...98 Authentication...
Страница 204: ...188 Administration To exit the CLI mode and return to ACS s shell issue the command cli quit...
Страница 268: ...252 Power Management with AlterPath PM Integration...
Страница 304: ...288 PCMCIA Cards Integration...
Страница 338: ...322 Profile Configuration...
Страница 364: ...348 Additional Features and Applications...
Страница 376: ...360 Appendix A New User Background Information...
Страница 406: ...390 Appendix C Cabling and Hardware Information This page has been left intentionally blank...
Страница 418: ...402 List of Tables...
Страница 420: ...404 List of Figures...