![Digi IX20 Скачать руководство пользователя страница 283](http://html.mh-extra.com/html/digi/ix20/ix20_user-manual_2496666283.webp)
Virtual Private Networks (VPN)
IPsec
IX20 User Guide
283
iv. Set the type of Diffie-Hellman group to use for key exchange during phase 1:
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)> dh_
group
value
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)>
where
value
is one of
ecp384
,
modp768
,
modp1024
,
modp1536
,
modp2048
,
modp3072
,
modp4096
,
modp6144
, or
modp8192
, . The default is
modp1024
.
v. (Optional) Add additional phase 1 proposals:
i. Move back one level in the schema:
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)>
..
(config vpn ipsec tunnel ipsec_example ike phase1_proposal)>
ii. Add an additional proposal:
(config vpn ipsec tunnel ipsec_example ike phase1_proposal)> add
end
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 1)>
Repeat the above steps to set the type of encryption, hash, and Diffie-Hellman
group for the additional proposal.
iii. Repeat to add more phase 1 proposals.
i. Configure the types of encryption, hash, and Diffie-Hellman group to use during phase 2:
i. Move back two levels in the schema:
(config vpn ipsec tunnel ipsec_example ike phase1_proposal 0)> .. ..
(config vpn ipsec tunnel ipsec_example ike)>
ii. Add a phase 2 proposal:
(config vpn ipsec tunnel ipsec_example ike)> add ike phase2_proposal
end
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
iii. Set the type of encryption to use during phase 2:
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
cipher
value
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
where
value
is one of
3des
,
aes128
,
aes192
,
aes256
, or
null
. The default is
3des
.
iv. Set the type of hash to use during phase 2 to verify communication integrity:
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)> hash
value
(config vpn ipsec tunnel ipsec_example ike phase2_proposal 0)>
where
value
is one of
md5
,
sha1
,
sha256
,
sha384
, or
sha512
. The default is
sha1
.
Содержание IX20
Страница 1: ...IX20 User Guide ...
Страница 598: ...Monitoring This chapter contains the following topics intelliFlow 599 Configure NetFlow Probe 606 IX20 User Guide 598 ...
Страница 613: ...Central management Configure Digi Remote Manager IX20 User Guide 613 ...
Страница 640: ...Diagnostics View system event logs IX20 User Guide 640 5 Click to download the system log ...
Страница 707: ...Command line interface Command line reference IX20 User Guide 707 more path The file to view Syntax STRING ...
Страница 710: ...Command line interface Command line reference IX20 User Guide 710 reboot Reboot the system Parameters None ...