Adaptec iSA1500 User Guide - Page 174

ipsec create commands, psk local, password, x509 [dn

Page 174 highlights

Using CLI psk local | (remote_host username [password password] location [name name]) The parameters to import a Public Shared Key are the same as for the RSA key file. However there is an option for that key to be the unit's local PSK in which case just the keyword local is used. x509 [dn dist_name] For a X509 connection the Distinguished Name which defines the certificate for the remote end must be supplied as the dist_name value of the dn parameter. An X509 connection cannot be created until the unit's local certificate has been loaded, probably by running the x509 import command. ipsec create commands These commands create new IPSec connections. They are not a context. They can be run as global commands by preceding them by ipsec create or by preceding them with create from the ipsec context. Table 8-24 lists all ipsec create commands. More details about each command appear after the Table. Table 8-24 ipsec create Commands Command dynamic host network opportunistic Parameters name id id psk | rsa | x509 policy_parameters name remote_host [id id] psk | rsa | x509 policy_parameters name remote_host remote_subnet [id id] psk | rsa | x509 policy_parameters [rsa] rsa_parameters Levels administrator administrator administrator administrator 8-35

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218

8-35
Using CLI
psk local | (
remote_host username
[password
password
]
location
[name
name
])
The parameters to import a Public Shared Key are the same as for
the RSA key file. However there is an option for that key to be the
unit's local PSK in which case just the keyword
local
is used.
x509 [dn
dist_name
]
For a X509 connection the Distinguished Name which defines the
certificate for the remote end must be supplied as the
dist_name
value of the
dn
parameter. An X509 connection cannot be created
until the unit's local certificate has been loaded, probably by
running the
x509 import
command.
ipsec create commands
These commands create new IPSec connections. They are not a
context. They can be run as global commands by preceding them
by
ipsec create
or by preceding them with
create
from the
ipsec
context.
Table 8-24
lists all ipsec create commands. More details about each
command appear after the Table.
Table 8-24
ipsec create Commands
Command
Parameters
Levels
dynamic
name id id psk | rsa | x509
policy_parameters
administrator
host
name remote_host [id
id] psk | rsa
| x509 policy_parameters
administrator
network
name remote_host remote_subnet
[id id] psk | rsa | x509
policy_parameters
administrator
opportunistic
[rsa] rsa_parameters
administrator