272
01-28007-0144-20041217
Fortinet Inc.
CLI configuration
VPN
Example
Use the following command to edit an IPSec VPN phase 1 configuration with the
following characteristics:
• Phase 1 configuration name:
Simple_GW
• Remote peer address type:
Dynamic
• Encryption and authentication proposal:
des-md5
• Authentication method:
psk
• Pre-shared key:
Qf2p3O93jIj2bz7E
• Mode:
aggressive
• Dead Peer Detection:
enable
• Long idle:
1000
• Short idle:
150
• Retry count:
5
• Retry interval:
30
config vpn ipsec phase1
edit Simple_GW
set Type dynamic
set proposal des-md5
set authmethod psk
set psksecret Qf2p3O93jIj2bz7E
set mode aggressive
set dpd enable
set dpd-idlecleanup 1000
set dpd-idleworry 150
set dpd-retrycount 5
set dpd-retryinterval 30
end
dpd-retrycount
<retry_integer>
The DPD retry count when
dpd
is set to
enable
. Set the number of times that the
local VPN peer sends a DPD probe before
it considers the link to be dead and tears
down the security association (SA). The
dpd-retrycount
range is 0 to 10.
To avoid false negatives due to congestion
or other transient failures, set the retry
count to a sufficiently high value for your
network.
3
All models.
dpd
must
be set to
enable
.
dpd-retryinterval
<seconds_integer>
The DPD retry interval when
dpd
is set to
enable
. Set the time, in seconds, that the
local VPN peer waits between sending DPD
probes. The
dpd-retryinterval
range
is 1 to 60.
5
seconds
All models.
dpd
must
be set to
enable
.
ipsec phase1 command keywords and variables (Continued)
Keywords and
variables
Description
Default
Availability
Содержание FortiGate FortiGate-60M
Страница 12: ...Contents 12 01 28007 0144 20041217 Fortinet Inc Index 369 ...
Страница 43: ...System status Changing the FortiGate firmware FortiGate 60M Administration Guide 01 28007 0144 20041217 43 ...
Страница 44: ...44 01 28007 0144 20041217 Fortinet Inc Changing the FortiGate firmware System status ...
Страница 74: ...74 01 28007 0144 20041217 Fortinet Inc FortiGate IPv6 support System network ...
Страница 82: ...82 01 28007 0144 20041217 Fortinet Inc Dynamic IP System DHCP ...
Страница 116: ...116 01 28007 0144 20041217 Fortinet Inc Access profiles System administration ...
Страница 234: ...234 01 28007 0144 20041217 Fortinet Inc Protection profile Firewall ...
Страница 246: ...246 01 28007 0144 20041217 Fortinet Inc CLI configuration Users and authentication ...
Страница 278: ...278 01 28007 0144 20041217 Fortinet Inc CLI configuration VPN ...
Страница 340: ...340 01 28007 0144 20041217 Fortinet Inc Using Perl regular expressions Spam filter ...
Страница 358: ...358 01 28007 0144 20041217 Fortinet Inc CLI configuration Log Report ...
Страница 376: ...376 01 28007 0144 20041217 Fortinet Inc Index ...