|
| Chapter 17 IPSec VPN |
|
|
|
| Table 70 Input Values for IPSec VPN Commands (continued) | |
| LABEL | DESCRIPTION |
| distinguished_name | A domain name. You can use up to 511 alphanumeric, characters, spaces, or .@=,_- |
|
| characters. |
|
|
|
| sort_order | Sort the list of currently connected SAs by one of the following classifications. |
|
| algorithm |
|
| encapsulation |
|
| inbound |
|
| name |
|
| outbound |
|
| policy |
|
| timeout |
|
| uptime |
The following sections list the IPSec VPN commands.
17.2.1 IKE SA Commands
This table lists the commands for IKE SAs (VPN gateways).
Table 71 isakmp Commands: IKE SAs
COMMAND | DESCRIPTION |
show isakmp keepalive | Displays the Dead Peer Detection period. |
show isakmp policy [policy_name] | Shows the specified IKE SA or all IKE SAs. |
isakmp keepalive <2..60> | Sets the Dead Peer Detection period. |
[no] isakmp policy policy_name | Creates the specified IKE SA if necessary and enters |
| mode. The no command deletes the specified IKE SA. |
activate | Activates or deactivates the specified IKE SA. |
deactivate |
|
authentication | Specifies whether to use a |
| authentication. |
certificate | Sets the certificate that can be used for authentication. |
[no] dpd | Enables Dead Peer Detection (DPD). The no command disables |
| DPD. |
[no] | Set this to have the ZyWALL reconnect to the primary address when |
| it becomes available again and stop using the secondary |
| connection, if the connection to the primary address goes down and |
| the ZyWALL changes to using the secondary connection. |
| Users will lose their VPN connection briefly while the ZyWALL |
| changes back to the primary connection. To use this, the peer |
| device at the secondary address cannot be set to use a |
| VPN connection. |
|
|
Sets how often (in seconds) the ZyWALL checks if the primary | |
| address is available. |
|
|
mode {main aggressive} | Sets the negotiating mode. |
Sets the encryption and authentication algorithms for each IKE SA | |
[isakmp_algo]] | proposal. |
| isakmp_algo: |
| |
| md5 |
|
|
lifetime <180..3000000> | Sets the IKE SA life time to the specified value. |
| 143 |
ZyWALL (ZLD) CLI Reference Guide | |
|
|