Chapter 28 IPSec VPN
ZyWALL / USG (ZLD) CLI Reference Guide
188
28.2.2 IPv4 IPSec SA Commands (except Manual Keys)
This table lists the commands for IPSec SAs, excluding manual keys (VPN connections using VPN
gateways).
group1
group2
group5
group14
Sets the DH
x
group to the specified group.
[no] natt
Enables NAT traversal. The
no
command disables NAT traversal.
local-ip {ip {
ip
|
domain_name
} |
interface
interface_name
}
Sets the local gateway address to the specified IP address, domain
name, or interface.
peer-ip {
ip
|
domain_name
} [
ip
|
domain_name
]
Sets the remote gateway address(es) to the specified IP
address(es) or domain name(s).
keystring
pre_shared_key
Sets the pre-shared key that can be used for authentication. The
pre_shared_key
can be:
•
8 - 32 alphanumeric characters or ,;|`~!@#$%^&*()_+\{}':./
<>=-".
•
16 - 64 hexadecimal (0-9, A-F) characters, preceded by “0x”.
The pre-shared key is case-sensitive.
local-id type {ip
ip
| fqdn
domain_name
|
e_mail
| dn
distinguished_name
}
Sets the local ID type and content to the specified IP address,
domain name, or e-mail address.
peer-id type {any | ip
ip
| fqdn
domain_name
e_mail
| dn
distinguished_name
}
Sets the peer ID type and content to any value, the specified IP
address, domain name, or e-mail address.
[no] xauth type {server
auth_method
|
client name
username
password
password
}
Enables extended authentication and specifies whether the ZyWALL
/ USG is the server or client. If the ZyWALL / USG is the server, it
also specifies the extended authentication method (
aaa
authentication
profile_name
); if the ZyWALL / USG is the
client, it also specifies the username and password to provide to the
remote IPSec router. The
no
command disables extended
authentication.
username
: You can use alphanumeric characters, underscores (_),
and dashes (-), and it can be up to 31 characters long.
password
: You can use most printable ASCII characters. You cannot
use square brackets [ ], double quotation marks (“), question marks
(?), tabs or spaces. It can be up to 31 characters long.
isakmp policy rename
policy_name
policy_name
Renames the specified IKE SA (first
policy_name
) to the specified
name (second
policy_name
).
Table 101
isakmp Commands: IKE SAs (continued)
COMMAND
DESCRIPTION
Table 102
crypto Commands: IPSec SAs
COMMAND
DESCRIPTION
[no] crypto ignore-df-bit
Fragment packets larger than the MTU (Maximum Transmission
Unit) that have the “don’t” fragment” bit in the header turned on.
The
no
command has the ZyWALL / USG drop packets larger than
the MTU that have the “don’t” fragment” bit in the header turned
on.
show crypto map [
map_name
]
Shows the specified IPSec SA or all IPSec SAs.
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...