264
Command syntax pattern
config vpn ipsec phase2
edit <name_str>
set <keyword> <variable>
end
config vpn ipsec phase2
edit <name_str>
unset <keyword>
end
config vpn ipsec phase2
delete <name_str>
end
get vpn ipsec phase2 [<name_str>]
show vpn ipsec phase2 [<name_str>]
ipsec phase2 command keywords and variables
Keywords & Variables
Description
Default
bindtoif<interface-
name_str>
This setting is not required for most configurations. The
setting binds the tunnel to a single network interface
(channel redundancy is disabled).
Null
concentrator
<name_str>
Select a concentrator if you want the tunnelto be part of a
hub and spoke VPN configuration that has already been
added to the freeGuard 100.
No default.
dhcp-ipsec {disable |
enable}
If the tunnel will service remote dialup clients that
broadcast a DHCP request when connecting to the
tunnel, enable dhcpipsec. The freeGuard 100 can relay
the request to an external DHCP server.
Disable
dhgrp {1 | 2 | 5}
Select the Diffie-Hellman group to proposefor Phase 2 of
the IPSec VPN connection. Select one of DH 1, 2 or 5.
The VPN peers must use the same DH Group.
5
dstaddr <name_str>
Enter the name of the firewall destination IP address that
corresponds to the recipient or network behind the remote
VPN peer.You must create the firewall address usingthe
config firewall addresscommand before you can select it
here. For more information, see “config firewall address”.
Null
Summary of Contents for freeGuard 100
Page 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Page 3: ......
Page 7: ......
Page 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Page 183: ...176...