Chapter 28 IPSec VPN
ZyWALL / USG (ZLD) CLI Reference Guide
194
[no] fall-back
Set this to have the ZyWALL / USG reconnect to the primary address when it
becomes available again and stop using the secondary connection, if the connection
to the primary address goes down and the ZyWALL / USG changes to using the
secondary connection. Users will lose their VPN connection briefly while the ZyWALL /
USG changes back to the primary connection. To use this, the peer device at the
secondary address cannot be set to use a nailed-up VPN connection.
fall-back-check-interval
<60..86400>
Sets how often (in seconds) the ZyWALL / USG checks if the primary address is
available.
transform-set isakmp-algo
[isakmp_algo
[isakmp_algo]]
Sets the encryption and authentication algorithms for each IKEv2 SA proposal.
isakmp_algo
: {
des-md5 | des-sha | 3des-md5 | 3des-sha | aes128-md5 |
aes128-sha | aes192-md5 | aes192-sha | aes256- md5 | aes256-sha |
aes256-sha256 | aes256-sha512
}
lifetime <180..3000000>
Sets the IKEv2 SA life time to the specified value.
group1
group2
group5
group14
group15
group16
group17
group18
Sets the DH group to the specified group.
local-ip {ip {ip |
domain_name} | interface
interface_name}
Sets the local gateway address to the specified IP address, domain name, or
interface.
peer-ip {ip | domain_name}
[ip | domain_name]
Sets the remote gateway address(es) to the specified IP address(es) or domain
name(s).
keystring pre_shared_key
Sets the pre-shared key that can be used for authentication. The pre_shared_key
can be:
•
8 - 32 alphanumeric characters or ,;|`~!@#$%^&*()_+\{}':./<>=-".
•
16 - 64 hexadecimal (0-9, A-F) characters, preceded by “0x”.
The pre-shared key is case-sensitive.
local-id type {ip ip |
fqdn domain_name | mail
e_mail | dn
distinguished_name}
Sets the local ID type and content to the specified IP address, domain name, or e-
mail address.
peer-id type {any | ip ip
| fqdn domain_name | mail
e_mail | dn
distinguished_name}
Sets the peer ID type and content to any value, the specified IP address, domain
name, or e-mail address.
eap auth_method
AUTH_METHOD
Sets auth method for EAP. Default value is
Mschapv2
.
[no] eap type {server
AAA_method user-id
{name|any}| client name
username {password
PASSWORD| encrypted-
password PASSWORD}
Enables extended authentication and specifies whether the ZyWALL/ USG is the
server or client. If the ZyWALL / USG is the server, it also specifies the AAA
authentication method (aaa authentication profile_name); if the ZyWALL / USG is
the client, it also specifies the username and password to provide to the remote
IPSec router. The no command disables extended authentication.
•
username: You can use alphanumeric characters, underscores (_), and dashes (-
), and it can be up to 31 characters long.
•
password: You can use most printable ASCII characters. You cannot use square
brackets [ ], double quotation marks (“), question marks (?), tabs or spaces. It
can be up to 31 characters long.
ikev2 policy rename
policy_name policy_name
Renames the specified IKEv2 SA (first policy_name) to the specified name (second
policy_name).
Table 107
sa Commands: IPv4 IKEv2 (continued)
COMMAND
DESCRIPTION
Содержание ZyWALL USG Series
Страница 19: ...19 PART I Introduction ...
Страница 20: ...20 ...
Страница 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Страница 39: ...39 PART II Reference ...
Страница 40: ...40 ...
Страница 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Страница 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Страница 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Страница 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Страница 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Страница 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Страница 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Страница 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Страница 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Страница 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Страница 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Страница 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Страница 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Страница 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Страница 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Страница 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Страница 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Страница 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Страница 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Страница 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Страница 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Страница 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Страница 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Страница 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Страница 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...