freeGuard 100 CLI User Manual
267
local VPN peer. You must create the firewall address
using the config firewall address command before you
can select it here. For more information, see “config
firewall address”.
srcport <port_integer>
Enter the port number that the local VPN peer uses to
transport traffic related to the specified service (see
protocol). The srcport range is 1 to 65535. To specify all
ports, type 0.
0
Example
Use the following command to add a phase 2 configuration with the following characteristics:
Name:
New_Tunnel
Phase 1 name:
Simple_GW
Encryption and authentication proposal:
3des-sha1 aes256-sha1 des-md5
Keylife
type:
seconds
Keylife
seconds:
18001
Diffie-Hellman
group:
2
Replay detection: enable
Perfect forward secrecy: enable
Keepalive: enable
config vpn ipsec phase2
edit New_Tunnel
set phase1name Simple_GW
set proposal 3des-sha1 aes256-sha1 des-md5
set keylife_type seconds
set keylifeseconds 18001
set dhgrp 2
set replay enable
set pfs enable
set keepalive enable
end
This example shows how to display the settings for the vpn ipsec phase2 command.
get vpn ipsec phase2
Summary of Contents for freeGuard 100
Page 1: ...freeGuard 100 UTM Firewall CLI USER S MANUAL P N F0025000 Rev 1 1...
Page 3: ......
Page 7: ......
Page 87: ...80 The config ips anomaly command has 1 subcommand config limit...
Page 183: ...176...