iSG4F
User’s Manual
iS5 Communications Inc.
135
-
rsA-signature import
{
flash:
<file name> |
sftp://
<user:password@<ip>/<file_name> |
tftp://<
ip>/<file_name> }
-
show rsA-signature list
+
ipsec
{
enable
|
disable
}
-
flush-sa proto
{ah | esp | ipsec | isakmp}
-
rsa-signature activate
{
crt-file
<file name> |
key-file
<file name>
|
rsa-sig-name
<name>}
+
isakmp update
- authentication-method {pre_shared_key | rsasig}
- dh-group
<none | modp768 | modp1024 | modp1536 | modp2048 |
modp3072 |modp4096 | modp6144>
-
pfs-group
< none | modp768 | modp1024 | modp1536 | modp2048
| modp3072 |modp4096 | modp6144 |modp8192>
-
dpd-delay
<5,0-120>
dpd-maxfail
<5,2-20>
dpd-retry
<5,1-20>
-
log-level
<error |warning |notify |info |debug |debug2>
-
my-id
<>
-
soft-lifetime
<1-99>
-
id-type
{none| fqdn}
-
ike-phase1-mode
<
aggressive
|main>
phase1-encryption-algo
<3des |
aes-128
| aes-256>
phase1-hash-algo
<md5 |
sha1
|sha256
|sha512>
-
phase2-auth-algo
< hmac_md5 | hmac_sha1 | hmac_sha256 |
hmac_sha512>
phase2-encryption-algo
<3des |aes-128
|aes-256>
- phase1-lifetime
<86400,(180-946080000)>
phase2-lifetime
<86400,(180-946080000)>
-
rsa-sig-name
<name>
+
policy
{create | remove | show}
src-address-prefix
<A.B.C.D/E>
dst-address-prefix
< A.B.C.D/E
>
src-port
<>
dst-port
<>
protocol
[gre |tcp |udp]
notes
[text]