Chapter 28 IPSec VPN
ZyWALL / USG (ZLD) CLI Reference Guide
187
The following sections list the IPSec VPN commands.
28.2.1 IPv4 IKEv1 SA Commands
This table lists the commands for IKE SAs (VPN gateways).
sort_order
Sort the list of currently connected SAs by one of the following classifications.
algorithm
encapsulation
inbound
name
outbound
policy
timeout
uptime
auth_method
The name of the authentication profile.
Table 100
Input Values for IPSec VPN Commands (continued)
LABEL
DESCRIPTION
Table 101
isakmp Commands: IKE SAs
COMMAND
DESCRIPTION
show isakmp keepalive
Displays the Dead Peer Detection period.
show isakmp policy [
policy_name
]
Shows the specified IKE SA or all IKE SAs.
[no] isakmp policy
policy_name
Creates the specified IKE SA if necessary and enters sub-command
mode. The
no
command deletes the specified IKE SA.
activate
deactivate
Activates or deactivates the specified IKE SA.
authentication {pre-share | rsa-sig |
user-base-psk }
Specifies whether to use a pre-shared key, a certificate, or a user-
based pre-shared key for authentication.
certificate
certificate-name
Sets the certificate that can be used for authentication.
[no] dpd
Enables Dead Peer Detection (DPD). The
no
command disables
DPD.
dpd-interval <15..60>
Sets the Dead Peer Detection (DPD) period.
[no] fall-back
Set this to have the ZyWALL / USG reconnect to the primary
address when it becomes available again and stop using the
secondary connection, if the connection to the primary address goes
down and the ZyWALL / USG changes to using the secondary
connection.
Users will lose their VPN connection briefly while the ZyWALL / USG
changes back to the primary connection. To use this, the peer
device at the secondary address cannot be set to use a nailed-up
VPN connection.
fall-back-check-interval <60..86400>
Sets how often (in seconds) the ZyWALL / USG checks if the
primary address is available.
mode {main | aggressive}
Sets the negotiating mode.
transform-set isakmp-algo [isakmp_algo
[
isakmp_algo
]]
Sets the encryption and authentication algorithms for each IKE SA
proposal.
isakmp_algo
: {des-md5 | des-sha | 3des-md5 | 3des-sha |
aes128-md5 | aes128-sha | aes192-md5 | aes192-sha | aes256-
md5 | aes256-sha | aes256-sha256 | aes256-sha512}
lifetime <180..3000000>
Sets the IKE SA life time to the specified value.
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...