Chapter 28 IPSec VPN
ZyWALL / USG (ZLD) CLI Reference Guide
197
28.2.10 IPv6 VPN Concentrator Commands
This table lists the commands for the IPv6 VPN concentrator.
scenario {site-to-site-static|site-to-
site-dynamic|remote-access-server|remote-
access-client}
Select the scenario that best describes your intended VPN
connection.
Site-to-site
: The remote IPSec router has a static IP address or
a domain name. This ZyWALL / USG can initiate the VPN tunnel.
site-to-site-dynamic
: The remote IPSec router has a dynamic
IP address. Only the remote IPSec router can initiate the VPN
tunnel.
remote-access-server
: Allow incoming connections from IPSec
VPN clients. The clients have dynamic IP addresses and are also
known as dial-in users. Only the clients can initiate the VPN tunnel.
remote-access-client
: Choose this to connect to an IPSec
server. This ZyWALL / USG is the client (dial-in user) and can
initiate the VPN tunnel.
set security-association lifetime seconds
<180..3000000>
Sets the IPSec SA life time.
set pfs {group1 | group2 | group5 | none}
Enables Perfect Forward Secrecy group.
local-policy
address_name
Sets the address object for the local policy (local network).
remote-policy
address_name
Sets the address object for the remote policy (remote network).
[no] policy-enforcement
Drops traffic whose source and destination IP addresses do not
match the local and remote policy. This makes the IPSec SA more
secure. The
no
command allows traffic whose source and
destination IP addresses do not match the local and remote policy.
Note: You must allow traffic whose source and destination IP
addresses do not match the local and remote policy, if you
want to use the IPSec SA in a VPN concentrator.
[no] nail-up
Automatically re-negotiates the SA as needed. The
no
command
does not.
[no] replay-detection
Enables replay detection. The
no
command disables it.
[no] configuration-payload-provide
activate
Enables configuration payload in server role. The
no
command
disables it.
configuration-payload-provide address-
pool {POOL}
Sets configuration payload address pool. The
no
command disables
it
[no] configuration-payload-provide
{first-dns IPv6|second-dns IPv6}
Sets configuration payload address pool dns server. The
no
command disables it
[no] narrowed
Enables policy narrowed. The
no
command disables it
Table 109
crypto Commands: IPv6 IPSec SAs (continued)
COMMAND
DESCRIPTION
Table 110
vpn-concentrator Commands: VPN Concentrator
COMMAND
DESCRIPTION
show vpn-concentrator6 [
profile_name
]
Shows the specified IPv6 VPN concentrator or all IPv6 VPN concentrators.
[no] vpn-concentrator6
profile_name
Creates the specified IPv6 VPN concentrator if necessary and enters sub-
command mode. The
no
command deletes the specified IPv6 VPN
concentrator.
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...