266
sha1}
• 3des-Triple-DES, in which plain text is encrypted three
times by three keys.
• aes128-A 128-bit block algorithm that uses a 128-bit
key.
• aes192-A 128-bit block algorithm that uses a 192-bit
key.
• aes256-A 128-bit block algorithm that uses a 256-bit
key. You can select either of the following message
digests to check the authenticity of messages during an
encrypted session:
• null-Do not use a message digest.
• md5-Message Digest 5, the hash algorithm developed
by RSA Data Security.
• sha1-Secure Hash Algorithm 1, which produces a 160-
bit message digest.
protocol
<protocol_integer>
Enter the IP protocol number for the service. The protocol
range is 1to 255. To specify all services, type 0.
0
replay {disable |
enable}
Optionally, enable or disable replay detection. Replay
attacks occur when an unauthorized party intercepts a
series of IPSec packets and replays them back into the
tunnel. Enable replay detection to check the sequence
number of every IPSec packet to see if it has been
received before. If packets arrive out of sequence, the
freeGuard 100s discards them. You can configure the
freeGuard 100 to send an alert email when it detects a
replay packet. See “config alert email”.
Disable
selector { policy |
specify | wildcard}
Enter the method for choosing selectors for IKE
negotiations:
• Select policy to choose a selector from a firewall
encryption policy. The VPN tunnel specified in the firewall
encryption policy will be referenced.
• Select specify to specify the firewall encryption policy
source and destination IP addresses, ports, and IP
protocol to use for selector negotiations. When you
choose specify, you must also enter values for the
srcaddr, dstaddr, protocol, srcport, and dstport keywords.
• Select wildcard to disable selector negotiation for this
tunnel. Use this option to avoid negotiation errors (such
as invalid ID information) when the set of policies
between the peers is not symmetric.
Policy
single-source {disable |
enable}
Enable or disable all dialup clients to connect using the
same phase 2 tunnel definition.
Disable
srcaddr <name_str>
Enter the name of the firewall source IP address that
corresponds to the local sender or network behind the
Null
Содержание freeGuard 100
Страница 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Страница 3: ......
Страница 7: ......
Страница 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Страница 183: ...176...
Страница 309: ...302 100 from a TFTP server with the address 192 168 21 54 set vpn certificates local import branch_cert 192 168 21 54...