![Fortinet FortiGate 1000A Скачать руководство пользователя страница 289](http://html.mh-extra.com/html/fortinet/fortigate-1000a/fortigate-1000a_administration-manual_2321799289.webp)
VPN
CLI configuration
FortiGate-1000A/FA2 Administration Guide
01-28011-0254-20051115
289
get vpn ipsec phase2 [<name_str>]
show vpn ipsec phase2 [<name_str>]
ipsec vip
A FortiGate unit can act as a proxy by answering ARP requests locally and forwarding
the associated traffic to the intended destination host over an IPSec VPN tunnel. The
feature is intended to enable IPSec VPN communications between two hosts that
coordinate the same private address space on physically separate networks. The IP
addresses of both the source host and the destination host must be unique. The
ipsec vip
command lets you specify the IP addresses that can be accessed at the
remote end of the VPN tunnel. You must configure IPSec virtual IP (VIP) addresses at
both ends of the IPSec VPN tunnel.
Adding an IPSec VIP entry to the VIP table enables a FortiGate unit to respond to
ARP requests destined for remote servers and route traffic to the intended
destinations automatically. Each IPSec VIP entry is identified by an integer. An entry
identifies the name of the FortiGate interface to the destination network, and the IP
address of a destination host on the destination network. Specify an IP address for
every host that needs to be accessed on the other side of the tunnel—you can define
a maximum of 32 IPSec VIP addresses on the same interface.
For more information, see
“Configuring IPSec virtual IP addresses” on page 290
.
Command syntax pattern
config vpn ipsec vip
edit <vip_integer>
set <keyword> <variable>
end
config vpn ipsec vip
edit <vip_integer>
unset <keyword>
end
config vpn ipsec vip
delete <vip_integer>
end
ipsec phase2 command keywords and variables
Keywords and variables
Description
Default
Availability
bindtoif
<interface-name_str>
Bind the tunnel to the specified
network interface. Type the name of
the local FortiGate interface.
null
All models.
single-source
{disable | enable}
Enable or disable all dialup clients to
connect using the same phase 2
tunnel definition.
disable
All models.
Note:
The interface to the destination network must be associated with a VPN tunnel through a
firewall encryption policy (
action
must be set to
encrypt
). The policy determines which VPN
tunnel will be selected to forward traffic to the destination. When you create IPSec VIP entries,
check the encryption policy on the FortiGate interface to the destination network to ensure that
it meets your requirements.
Содержание FortiGate 1000A
Страница 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Страница 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Страница 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Страница 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Страница 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Страница 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Страница 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...