THOMSON SpeedTouch 608WL Configuration Manual page 217

Wireless business dsl router ipsec configuration guide
Hide thumbs Also See for SpeedTouch 608WL:
Table of Contents

Advertisement

Local match
[localmatch]
E-DOC-CTC-20051017-0169 v0.1
This setting is relevant in responder mode only.
It is optionally filled out. In a basic configuration it is left unset. When unset, the
SpeedTouch™ uses its dynamic IPSec policy capabilities to complete this field. The
ipsec connection advanced
this parameter.
The localmatch expresses the traffic policy for access to the local private network in
responder mode. It describes which IP addresses, address ranges or subnets at the
local side have access to the Security Association. During the Phase 2 negotiations,
the proposals of the remote peer (initiator) are compared with the contents of the
localmatch parameter. As a result, a local traffic selector is derived in compliance
with the local and remote traffic policies.
The valid values for the localmatch parameter are limited to specific keywords,
eventually followed by a network name.
Keyword:
exactly_
one_of_
subnet_of_
subrange_of_
black_ip
The meaning of the keywords is the following:
exactly_<network name>:
The proposal issued by the remote initiator must exactly match the network
described by the symbolic network name. This network descriptor can
designate an individual IP address, an IP address range, or an IP subnet. If the
proposal of the remote initiator does not exactly match the designated net,
then the local responder does not establish a Security Association.
one_of_ <network name>:
The proposal of the remote initiator must contain an IP address that lies within
the range described by the symbolic network name in order to successfully set
up the Security Association.
subnet_of_ <network name>:
The proposal of the remote initiator must contain a subnet that lies within the
range described by the symbolic network name in order to successfully set up
the Security Association.
subrange_of_ <network name>:
The proposal of the remote initiator must contain a subrange that lies within
the range described by the symbolic network name in order to successfully set
up the Security Association.
black_ip:
The proposal of the remote initiator must contain the public IP address of the
SpeedTouch™.
command group allows manual control over
Followed by a Network name:
A symbolic name of a network
descriptor, defined in the
connection network
group.
-
Chapter 6
Advanced Features
ipsec
command
215

Advertisement

Table of Contents
loading

This manual is also suitable for:

Speedtouch 620

Table of Contents