Ike Sa Commands - ZyXEL Communications UAG Series User Manual

Unified access gateway
Hide thumbs Also See for UAG Series:
Table of Contents

Advertisement

Table 102 Input Values for IPSec VPN Commands (continued)
LABEL
distinguished_name
sort_order
The following sections list the IPSec VPN commands.

34.2.1 IKE SA Commands

This table lists the commands for IKE SAs (VPN gateways).
Table 103 isakmp Commands: IKE SAs
COMMAND
show isakmp keepalive
show isakmp policy [policy_name]
isakmp keepalive <2..60>
[no] isakmp policy policy_name
activate
deactivate
authentication {pre-share | rsa-sig}
certificate certificate-name
[no] dpd
[no] fall-back
fall-back-check-interval <60..86400>
mode {main | aggressive}
transform-set isakmp-algo [isakmp_algo
[isakmp_algo]]
lifetime <180..3000000>
UAG CLI Reference Guide
DESCRIPTION
A domain name. You can use up to 511 alphanumeric, characters, spaces, or .@=,_-
characters.
Sort the list of currently connected SAs by one of the following classifications.
algorithm
encapsulation
inbound
name
outbound
policy
timeout
uptime
DESCRIPTION
Displays the Dead Peer Detection period.
Shows the specified IKE SA or all IKE SAs.
Sets the Dead Peer Detection period.
Creates the specified IKE SA if necessary and enters sub-command
mode. The
Activates or deactivates the specified IKE SA.
Specifies whether to use a pre-shared key or a certificate for
authentication.
Sets the certificate that can be used for authentication.
Enables Dead Peer Detection (DPD). The
DPD.
Set this to have the UAG reconnect to the primary address when it
becomes available again and stop using the secondary connection, if
the connection to the primary address goes down and the UAG
changes to using the secondary connection.
Users will lose their VPN connection briefly while the UAG changes
back to the primary connection. To use this, the peer device at the
secondary address cannot be set to use a nailed-up VPN connection.
Sets how often (in seconds) the UAG checks if the primary address
is available.
Sets the negotiating mode.
Sets the encryption and authentication algorithms for each IKE SA
proposal.
isakmp_algo: {des-md5 | des-sha | 3des-md5 | 3des-sha |
aes128-md5 | aes128-sha | aes192-md5 | aes192-sha | aes256-
md5 | aes256-sha | aes256-sha256 | aes256-sha512}
Sets the IKE SA life time to the specified value.
command deletes the specified IKE SA.
no
Chapter 34 IPSec VPN
command disables
no
177

Advertisement

Table of Contents
loading

Table of Contents