117
6620-3201
Using Text Commands
From the command line, use the
eroute
command to con
fi
gure or display Eroute settings. To
display current settings for a speci
fi
c Eroute, enter the command:
eroute <eroute> ?
where
<eroute>
is the number of the eroute. To change the value of a
parameter use the command in the format:
eroute <eroute> <parameter> <value>
The parameters and values are: For example, to set the IP address of the remote unit for Eroute 2 to
192.168.100.1 you would enter:
Parameter
Values
Equivalent Web Parameter
ahauth
off, md5, sha1
AH authentication algorithm
apnbu 0,1
Interface must use this APN:
0=Main APN 1=Backup APN
authmeth
off, preshared, rsa Authentication method
autosa
off, on
Create SA’s automatically
check_apnbu
off, on
Check APN usage
dhgroup
0,1,2,3
IPSec MODP group
enckeybits
number
ESP encrypt key length (bits)
espauth
off, md5, sha1
ESP authentication algorithm
espenc
off, des, 3des, aes ESP encryption algorithm
gre
off, on
GRE
idisfqdn
no, yes
Send our ID as FQDN
ifadd
number
Link eroute with interface #
ifent
blank, ppp, eth
Link eroute with interface
ikecfg 0,1 IKE
con
fi
g to use when initiator
ikever 1,2 IKE
version
intunnel off,
on
This eroute is tunnelled within
another eroute
ipcompalg off,
de
fl
ate
IPCOMP algorithm
lkbytes number
Duration
(kb)
loc
fi
rstport
0-65535
First local port (IKEv2 only)
locip
IP address
Local subnet IP address
locipifadd
blank, ppp, eth
Interface to use for local subnet IP
address
locipifent number
Interface # to use for local subnet
IP address
loclastport
0-65535
Last local port (IKEv2 only)
locmsk
subnet mask
Local subnet mask
locport number
Local
port
ltime 0-28800
Duration
(s)
mode tunnel,
transport
Mode
natkaint
number
NAT keep alive interval (s)
neglocip IP
address
Local subnet IP address to
negotiate (if different from above)
neglocmsk subnet
mask
Local subnet mask to negotiate (if
different from above)
nosa
drop, pass, try
No SA action