Administrator’s Handbook

set security ipsec tunnels name "123" dest-int-networkip-address

Specifies the IP address of the destination computer or internal network.

set security ipsec tunnels name "123" dest-int-netmasknetmask

Specifies the subnet mask of the destination computer or internal network. The subnet mask specifies which bits of the 32-bit IP address represents network information. The default subnet mask for most net- works is 255.255.255.0 (class C subnet mask).

set security ipsec tunnels name "123" encrypt-protocol (ESP) { ESP none }

See page 146 for details about SafeHarbour IPsec tunnel capability.

set security ipsec tunnels name "123" auth-protocol (ESP) {AH ESP none}

See page 146 for details about SafeHarbour IPsec tunnel capability.

set security ipsec tunnels name "123" IKE-mode pre-shared-key-type (hex) {ascii hex}

See page 146 for details about SafeHarbour IPsec tunnel capability.

set security ipsec tunnels name "123" IKE-mode pre-shared-key ("") {hex string}

See page 146 for details about SafeHarbour IPsec tunnel capability.

Example: 0x1234

set security ipsec tunnels name "123" IKE-mode neg-method {main aggressive}

See page 146 for details about SafeHarbour IPsec tunnel capability.

Note: Aggressive Mode is a little faster, but it does not provide identity protection for negotiations nodes.

set security ipsec tunnels name "123" IKE-mode DH-group (1) { 1 2 5}

See page 146 for details about SafeHarbour IPsec tunnel capability.

288

Page 288
Image 288
Motorola 3342, 7000, 3352N, 2200 manual Set security ipsec tunnels name 123 IKE-mode DH-group 1 1 2, 288