
Configuration Objects
156
H.2.44. ipsec-proposal: IPsec AH/ESP proposal
Proposal for establishing the IPsec AH/ESP keying information
Table H.58. ipsec-proposal: Attributes
Attribute
Type
Default
Description
DHset
Set of ike-DH
Accept
any
supported group
Diffie-Hellman group for IPsec key
negotiation
ESN
Set of ike-ESN
Accept ESN or short
SN
Support for extended sequence numbers
authset
Set of ipsec-auth-
algorithm
Accept
any
supported algorithm
Integrity check algorithm for IPsec traffic
cryptset
Set of ipsec-crypt-
algorithm
Accept
any
supported algorithm
Encryption algorithm for IPsec traffic
name
Not optional
Name
H.2.45. ipsec-manual: peer configuration
IPsec manually keyed connection settings (not recommended, use IKEv2 and secrets instead)
Table H.59. ipsec-manual: Attributes
Attribute
Type
Default
Description
bgp
Not announced
BGP announce mode for routes
comment
-
Comment
graph
(token) graphname
-
Graph name
internal-ipv4
local-ip
Internal IPv4 for traffic originated on the
FireBrick and sent down tunnel
internal-ipv6
local-ip
Internal IPv6 for traffic originated on the
FireBrick and sent down tunnel
local-ip
-
Local IP
localpref
4294967295
Localpref for route (highest wins)
log
Not logging
Log events
log-debug
Not logging
Log debug
log-error
Log as event
Log errors
mtu
1500
MTU for wrapped packets
name
-
Name
payload-table
(unsignedByte 0-99)
routetable
0
Routing table number for payload traffic
peer-ips
List
of
Accept
from
anywhere
peer's IP or range
profile
-
Profile name
routes
List of IPPrefix
-
Routes when link up
source
-
Source of data, used in automated config
management
speed
no shaping
Egress rate limit used (b/s)
Содержание FB6402
Страница 1: ...FireBrick FB6402 User Manual FB6000 Versatile Network Appliance...
Страница 2: ......