Chapter 28 IPSec VPN
ZyWALL / USG (ZLD) CLI Reference Guide
190
[no] policy-enforcement
Drops traffic whose source and destination IP addresses do not
match the local and remote policy. This makes the IPSec SA more
secure. The
no
command allows traffic whose source and
destination IP addresses do not match the local and remote policy.
Note: You must allow traffic whose source and destination IP
addresses do not match the local and remote policy, if you
want to use the IPSec SA in a VPN concentrator.
[no] nail-up
Automatically re-negotiates the SA as needed. The
no
command
does not.
[no] replay-detection
Enables replay detection. The
no
command disables it.
[no] netbios-broadcast
Enables NetBIOS broadcasts through the IPSec SA. The
no
command disables NetBIOS broadcasts through the IPSec SA.
[no] out-snat activate
Enables out-bound traffic SNAT over IPSec. The
no
command
disables out-bound traffic SNAT over IPSec.
out-snat source
address_name
destination
address_name
snat
address_name
Configures out-bound traffic SNAT in the IPSec SA.
[no] in-snat activate
Enables in-bound traffic SNAT in the IPSec SA. The
no
command
disables in-bound traffic SNAT in the IPSec SA.
in-snat source
address_name
destination
address_name
snat
address_name
Configures in-bound traffic SNAT in the IPSec SA.
[no] in-dnat activate
Enables in-bound traffic DNAT in the IPSec SA. The
no
command
disables in-bound traffic DNAT in the IPSec SA.
in-dnat delete <1..10>
Deletes the specified rule for in-bound traffic DNAT in the specified
IPSec SA.
in-dnat move <1..10> to <1..10>
Moves the specified rule (first rule number) to the specified
location (second rule number) for in-bound traffic DNAT.
in-dnat append protocol {all | tcp | udp}
original-ip
address_name
<0..65535>
<0..65535> mapped-ip
address_name
<0..65535> <0..65535>
Maps the specified IP address and port range (original-ip) to the
specified IP address and port range (mapped-ip) and appends this
rule to the end of the rule list for in-bound traffic DNAT.
in-dnat insert <1..10> protocol {all |
tcp | udp} original-ip
address_name
<0..65535> <0..65535> mapped-ip
address_name
<0..65535> <0..65535>
Maps the specified IP address and port range (original-ip) to the
specified IP address and port range (mapped-ip) and inserts this
rule before the specified rule.
in-dnat <1..10> protocol {all | tcp |
udp} original-ip
address_name
<0..65535>
<0..65535>
mapped-ip address_name
<0..65535> <0..65535>
Creates or revises the specified rule and maps the specified IP
address and port range (original-ip) to the specified IP address and
port range (mapped-ip).
[no] configuration-payload-provide
activate
Enables configuration payload in server role. The
no
command
disables it.
configuration-payload-provide address-
pool {POOL}
Sets configuration payload address pool. The
no
command disables
it
[no] configuration-payload-provide
{first-dns IPv6|second-dns IPv6}
Sets configuration payload address pool dns server. The
no
command disables it
[no] narrowed
Enables policy narrowed. The
no
command disables it.
[no] protocol gre
Enables GRE over IPSec to allow traffic using the Generic Routing
Encapsulation (GRE) tunneling protocol through an IPSec tunnel.
The
no protocol
command disables it.
Table 102
crypto Commands: IPSec SAs (continued)
COMMAND
DESCRIPTION
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...