Ipsec settings
Connection description
Options supported by wcclite is described below.
Item
Type
Description
Gateway
string
Host name or IP address of the remote peer.
Type
selector
Tunnel mode: full packet encryption, covers hosttohost,
hosttosubnet, subnettosubnet situations or transport
mode: ip payload encryption, secures hosttohost data
only.
Local subnet
string
Specifies local network, in form network/netmask, for
example 192.168.11.0/24
Remote subnet
string
Specifies remote network at another side of a tunnel.
Authentication
selector
Preshared key or RSA certificate
Preshared key
string
Available if Authentication set to Preshared key
Certificate set
selector
Available if Authentication set to RSA certificate. Selectable
from configured auxiliary set.
Phase 1 proposal
(IKE)
selector
Authenticationencryption
schema,
selectable
from
configured auxiliary set.
Phase 2 proposal
(ESP)
selector
Authenticationencryption
schema,
selectable
from
configured auxiliary set.
Local ID
string
Specifies the identity of the local endpoint
Remote ID
string
Specifies the identity of the remote endpoint
Key exchange
selector
Sets method of key exchange IKEv2 or IKEv1. Default IKEv2.
Exchange mode
selector
Main or aggressive. Available if key exchange is set to IKEv1.
Use compression
checkbox
If selected a compression ability will be proposed to the peer.
DPD action
selector
Controls the use of dead peer detection protocol, values:
• none – default, disables sending of DPD messages.
• clear – the connection closed with no action.
• hold – keeps description, tries renegotiate connection
on demand.
• restart – will try to renegotiate immediately.
64