256
encryption {3des |
aes128 | aes192 |
aes256 | des | null}
Select an encryption algorithm from the list. Make
sure you use the samealgorithm at both ends of
the tunnel.
null
enckey <encryption-
key_hex>
If encryption is des, enter a 16 digit (8 byte)
hexadecimal number. If encryption is 3des, enter
a 48 digit (24 byte) hexadecimal number. If
encryptionis aes128, enter a 32 digit (16 byte)
hexadecimal number. If encryptionis aes192,
enter a 48 digit (24 byte) hexadecimal number. If
encryptionis aes256, enter a 64 digit (32 byte)
hexadecimal number. Digits can be 0 to 9, and a
to f. For all of the above, separate each 16 digit (8
byte) hexadecimal segment with a hyphen. Use
the same encryption key at both ends of the
tunnel.
No default.
gateway
<address_ipv4>
The IP address of the remote gateway external
interface.
0.0.0.0
localspi
<spi_hex>
Local Security Parameter Index. Enter a
hexadecimal number of up to eight digits(digits
can be 0 to 9, a to f) in the rangebb8 to FFFFFFF.
This number must be added to the Remote SPI at
the opposite end of the tunnel.
0x0
remotespi
<spi_hex>
emote Security Parameter Index. Enter a
hexadecimal number of up to eight digitsin the
range bb8 to FFFFFFF. This number must be
added to the Local SPI at the opposite end of the
tunnel.
0x0
Example
Use the following command to add an IPSec VPN manual key tunnel with the following characteristics:
Tunnel name: Manual_Tunnel
Local
SPI:
1000ff
Remote
SPI:
2000ff
Remote gateway IP address:
206.37.33.45
Encryption algorithm: 3DES
Encryption
keys:
003f2b01a9002f3b 004f4b0209003f01 3b00f23bff003eff
Authentication algorithm: MD5
Authentication
keys:
ff003f012ba900bb 00f402303f0100ff
config vpn ipsec manualkey
edit Manual_Tunnel
Summary of Contents for freeGuard 100
Page 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Page 3: ......
Page 7: ......
Page 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Page 183: ...176...