VPN
CLI configuration
FortiGate-60M Administration Guide
01-28007-0144-20041217
273
ipsec phase2
Use the
config vpn ipsec phase2
CLI command to add or edit an IPSec VPN
phase 2 configuration.
Command syntax pattern
config vpn ipsec phase2
edit <name_str>
set <keyword> <variable>
end
config vpn ipsec phase2
edit <name_str>
unset <keyword>
end
config vpn ipsec phase2
delete <name_str>
end
get vpn ipsec phase2 [<name_str>]
show vpn ipsec phase2 [<name_str>]
ipsec phase2 command keywords and variables
Keywords and variables
Description
Default
Availability
bindtoif
<interface-name_str>
Bind the tunnel to the specified
network interface. Type the name of
the local FortiGate interface.
No
default.
All models.
dstaddr <name_str>
Enter the name of the firewall
destination IP address that
corresponds to the
recipient or
network behind the remote VPN
peer.
You must create the firewall
address before you can select it here.
For more information, see
“Adding
firewall policies for IPSec VPN
tunnels” on page 268
.
No
default.
All models.
selector
must be set
to
specify
.
dstport
<port_integer>
Enter the port number that the remote
VPN peer uses to transport traffic
related to the specified service (see
protocol
). The
dstport
range is
1
to
65535
. To specify all ports, type
0
.
No
default.
All models.
selector
must be set
to
specify
.
protocol
<protocol_integer>
Enter the IP protocol number for the
service. The
protocol
range is
1
to
255
. To specify all services, type
0
.
No
default.
All models.
selector
must be set
to
specify
.
Summary of Contents for FortiGate FortiGate-60M
Page 12: ...Contents 12 01 28007 0144 20041217 Fortinet Inc Index 369 ...
Page 44: ...44 01 28007 0144 20041217 Fortinet Inc Changing the FortiGate firmware System status ...
Page 74: ...74 01 28007 0144 20041217 Fortinet Inc FortiGate IPv6 support System network ...
Page 82: ...82 01 28007 0144 20041217 Fortinet Inc Dynamic IP System DHCP ...
Page 116: ...116 01 28007 0144 20041217 Fortinet Inc Access profiles System administration ...
Page 234: ...234 01 28007 0144 20041217 Fortinet Inc Protection profile Firewall ...
Page 246: ...246 01 28007 0144 20041217 Fortinet Inc CLI configuration Users and authentication ...
Page 278: ...278 01 28007 0144 20041217 Fortinet Inc CLI configuration VPN ...
Page 340: ...340 01 28007 0144 20041217 Fortinet Inc Using Perl regular expressions Spam filter ...
Page 358: ...358 01 28007 0144 20041217 Fortinet Inc CLI configuration Log Report ...
Page 376: ...376 01 28007 0144 20041217 Fortinet Inc Index ...