_______________________________________________________________________________________________________
_______________________________________________________________________________________________________
© Virtual Access 2018
GW6600 Series User manual
Issue: 1.7
Page 359 of 519
32.2.5
Configure secret settings
Each tunnel requires settings to configure how the local end point of the tunnel proves
its identity to the remote end point.
Figure 176: IPSec secrets settings
Web Field/UCI/Package Option
Description
Web: Enabled
UCI: strongswan.@secret[X].enabled
Opt: enabled
Defines whether this set of credentials is to be used or not.
0
Disabled.
1
Enabled.
Web: ID selector
UCI: strongswan.@secret[X].idtype
Opt: idtype
Defines whether IP address or userfqdn is used.
Web: ID selector
UCI: strongswan.@secret[X].localaddress
Opt: localaddress
Defines the local address this secret applies to.
Web: ID selector
UCI: strongswan.@secret[X].
remoteaddress
Opt: remoteaddress
Defines the remote address this secret applies to.
Web: N/A
UCI: strongswan.@secret[X].userfqnd
Opt: userfqnd
FQDN or Xauth name used of Extended Authentication. This must
match xauth_identity from the configuration connection section.
Web: Secret Type
UCI: strongswan.@secret[X].secrettype
Opt: secrettype
Specifies the authentication mechanism to be used by the two
peers.
Psk
Preshared secret
Pubkey
Public key signatures
Rsasig
RSA digital signatures
Ecdsasig
Elliptic Curve DSA signatures
Xauth
Extended authentication
Web: Secret
UCI: strongswan.@secret[X].secret
Opt: secret
Defines the secret.
Table 130: Information table for IPSec secrets settings