D-Link DFL-260E CLI Guide for DFL-260E - Page 126

Transport mode. Default: Tunnel

Page 126 highlights

3.28.5. IPsecTunnel LocalNetwork RemoteNetwork RemoteEndpoint IKEAlgorithms IPsecAlgorithms IKELifeTimeSeconds IPsecLifeTimeSeconds IPsecLifeTimeKilobytes EncapsulationMode AuthMethod PSK LocalIDType LocalIDValue GatewayCertificate RootCertificates IDList DHCPOverIPsec AddRouteToRemoteNet PlaintextMTU OriginatorIPType Chapter 3. Configuration Reference The network on "this side" of the IPsec tunnel. The IPsec tunnel will be established between this network and the remote network. The network connected to the remote gateway. The IPsec tunnel will be established between the local network and this network. Specifies the IP address of the remote endpoint. This is the address the security gateway will establish the IPsec tunnel to. It also dictates from where inbound IPsec tunnels are allowed. (Optional) Specifies the IKE Proposal list used with the tunnel. Specifies the IPsec Proposal list used with the tunnel. The lifetime of the IKE connection in seconds. Whenever it expires, a new phase-1 exchange will be performed. (Default: 28800) The lifetime of the IPsec connection in seconds. Whenever it's exceeded, a re-key will be initiated, providing new IPsec encryption and authentication session keys. (Default: 3600) The lifetime of the IPsec connection in kilobytes. (Default: 0) Specifies if the IPsec tunnel should use Tunnel or Transport mode. (Default: Tunnel) Certificate or Pre-shared key. Selects the Pre-shared key to use with this IPsec Tunnel. Selects the type of Local ID to use. (Default: Auto) Specify the local identity of the tunnel ID. Selects the certificate the security gateway uses to authenticate itself to the other IPsec peer. Selects one or more root certificates to use with this IPsec Tunnel. Selects the identification list to use with this IPsec Tunnel. An identification list is a list of the identities that are allowed to establish a IPsec tunnel. (Optional) Allow DHCP over IPsec from single-host clients. (Default: No) Dynamically add route to the remote networks when a tunnel is established. (Default: No) Specifies the size in bytes at which to fragment plaintext packets (rather than fragmenting IPsec). (Default: 1420) Specifies what IP address to use as source IP in e.g. 126

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198

LocalNetwork
The network on "this side" of the IPsec tunnel. The
IPsec tunnel will be established between this net-
work and the remote network.
RemoteNetwork
The network connected to the remote gateway. The
IPsec tunnel will be established between the local
network and this network.
RemoteEndpoint
Specifies the IP address of the remote endpoint. This
is the address the security gateway will establish the
IPsec tunnel to. It also dictates from where inbound
IPsec tunnels are allowed. (Optional)
IKEAlgorithms
Specifies the IKE Proposal list used with the tunnel.
IPsecAlgorithms
Specifies the IPsec Proposal list used with the tun-
nel.
IKELifeTimeSeconds
The lifetime of the IKE connection in seconds.
Whenever it expires, a new phase-1 exchange will be
performed. (Default: 28800)
IPsecLifeTimeSeconds
The lifetime of the IPsec connection in seconds.
Whenever it's exceeded, a re-key will be initiated,
providing new IPsec encryption and authentication
session keys. (Default: 3600)
IPsecLifeTimeKilobytes
The lifetime of the IPsec connection in kilobytes.
(Default: 0)
EncapsulationMode
Specifies if the IPsec tunnel should use Tunnel or
Transport mode. (Default: Tunnel)
AuthMethod
Certificate or Pre-shared key.
PSK
Selects the Pre-shared key to use with this IPsec
Tunnel.
LocalIDType
Selects the type of Local ID to use. (Default: Auto)
LocalIDValue
Specify the local identity of the tunnel ID.
GatewayCertificate
Selects the certificate the security gateway uses to
authenticate itself to the other IPsec peer.
RootCertificates
Selects one or more root certificates to use with this
IPsec Tunnel.
IDList
Selects the identification list to use with this IPsec
Tunnel. An identification list is a list of the identities
that
are
allowed
to
establish
a
IPsec
tunnel.
(Optional)
DHCPOverIPsec
Allow DHCP over IPsec from single-host clients.
(Default: No)
AddRouteToRemoteNet
Dynamically add route to the remote networks when
a tunnel is established. (Default: No)
PlaintextMTU
Specifies the size in bytes at which to fragment
plaintext packets (rather than fragmenting IPsec).
(Default: 1420)
OriginatorIPType
Specifies what IP address to use as source IP in e.g.
3.28.5. IPsecTunnel
Chapter 3. Configuration Reference
126