![Freedom9 freeGuard 100 Скачать руководство пользователя страница 277](http://html1.mh-extra.com/html/freedom9/freeguard-100/freeguard-100_command-line-interface-manual_2329994277.webp)
270
This example shows how to display the settings for the VIP entry named 1.
get vpn ipsec vip 1
This example shows how to display the current configuration of all existing VIP entries.
show vpn ipsec vip
Related Commands
config vpn ipsec phase1
config vpn ipsec phase2
12.6 l2tp
Use this command to enable L2TP and specify a local address range to reserve for remote L2TP
clients. When a remote L2TP client connects to the internal network through a L2TP VPN, the client is
assigned an IP address from the specified range.
L2TP clients must authenticate with the freeGuard 100 when a L2TP session starts. To support L2TP
authentication on the freeGuard 100, you must define the L2TP users who need access and then add
them to a user group. For more information, see “config user group”, “config user ldap” , “config user
local” and “config user radius”.
You need to define a firewall policy to control services inside the L2TP tunnel. For more information,
see “config firewall” . When you define the firewall policy:
Create an external -> internal policy.
Set the source address to match the L2TP address range.
Set the destination address to reflect the private address range of the internal network behind
the local freeGuard 100.
Set the policy service(s) to match the type(s) of traffic that L2TP users may generate.
Set the policy action to accept.
Enable NAT if required.
Note
: The first time you configure the L2TP address range you must enter a starting IP, an ending IP,
and a user group.
Note: You can configure L2TP VPNs on freeGuard 100s that run in NAT/Route mode.
Command syntax pattern
config vpn l2tp
set <keyword> <variable>
end
config vpn l2tp
unset <keyword>
Содержание freeGuard 100
Страница 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Страница 3: ......
Страница 7: ......
Страница 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Страница 183: ...176...
Страница 309: ...302 100 from a TFTP server with the address 192 168 21 54 set vpn certificates local import branch_cert 192 168 21 54...