Patton electronics SmartWare R.3.20 Software Configuration Manual page 285

Software for smartnode series
Table of Contents

Advertisement

SmartWare Software Configuration Guide
Mode: Configure
Step
node (cfg)#profile ipsec-policy-man-
1
ual name
2
node (pf-ipstr)[name]#use profile
ipsec-transform name
node (pf-ipstr)[ name ]#session-key
3
optional
{ inbound | outbound }
{ ah-aauthentication | esp-
authentication | esp-encryption } key
node (pf-ipstr)[ name ]#spi
4
{ inbound | outbound } { ah | esp } spi
node (pf-ipstr)[ name ]#peer ip-address
5
node (pf-ipstr)[ name ]#mode
6
{ tunnel | transport }
Use no in front of the above commands to delete a profile or a configuration entry.
VPN configuration task list
Command
Purpose
Creates the IPsec policy profile name
Selects the IPsec transformation profile to be
applied
Sets a key for encryption or an authenticator for
authentication, either for inbound or outbound
direction. The key shall consist of hexadecimal
digits (0..9, A..F); one digit holds 4 Bit of key
information.
The key setting must match definitions in the
respective IPsec transformation profile. In particu-
lar, the length of the key or authenticator must
match the implicit (see section
on page 282 and
"Encryption"
explicit specification.
Keys must be available for inbound and out-
bound directions. They can be different for the
two directions. Make sure that the inbound key
of one peer matches the outbound key of the
other peer.
Sets the SPI for encryption (esp) or authentication
(ah), either for inbound or outbound direction.
The SPI shall be a decimal figure in the range
1..2
–1.
32
SPIs must be available for encryption and/or
authentication as specified in the respective IPsec
transformation profile.
SPIs must be available for inbound and outbound
directions. They can be identical for the two
directions but must be unique in one direction.
Make sure that the inbound SPI of one peer
matches the outbound SPI of the other peer.
Sets the IP address of the peer
The peers of the secured
Note
communication must have
static IP address. DNS reso-
lution is not available yet.
Selects tunnel or transport mode
25 • VPN configuration
"Authentication"
on page 282) or
285

Advertisement

Table of Contents
loading

This manual is also suitable for:

Smartware release 3.20

Table of Contents