D-Link DFL-800 CLI Guide - Page 104

Certificate or Pre-shared key. Default: PSK

Page 104 highlights

3.24.5. IPSecTunnel Chapter 3. Configuration Reference Name Equivalent Members Comments Specifies a symbolic name for the interface. (Identifier) Specifies if the interfaces should be considered security equivalent, that means that if enabled the interface group can be used as a destination interface in rules where connections might need to be moved between the two interfaces. (Default: No) Specifies the interfaces that are included in the interface group. Text describing the current object. (Optional) 3.24.5. IPSecTunnel Description An IPsec tunnel item is used to define IPsec endpoint and will appear as a logical interface in the system. Properties Index Name LocalNetwork RemoteNetwork RemoteEndpoint IKEConfigModePool IKEAlgorithms IPSecAlgorithms IKELifeTimeSeconds IPSecLifeTimeSeconds IPSecLifeTimeKilobytes EncapsulationMode AuthMethod PSK The index of the object, starting at 1. (Identifier) Specifies a symbolic name for the interface. The network on "this side" of the IPsec tunnel. The IPsec tunnel will be established between this network and the remote network. The network connected to the remote gateway. The IPsec tunnel will be established between the local network and this network. Specifies the IP address of the remote endpoint. This is the address the security gateway will establish the IPsec tunnel to. It also dictates from where inbound IPsec tunnels are allowed. (Optional) Selects IKE Config Mode Pool to use for the tunnel. (Optional) Specifies the IKE Proposal list used with the tunnel. Specifies the IPsec Proposal list used with the tunnel. The lifetime of the IKE connection in seconds. Whenever it expires, a new phase-1 exchange will be performed. (Default: 28800) The lifetime of the IPsec connection in seconds. Whenever it's exceeded, a re-key will be initiated, providing new IPsec encryption and authentication session keys. (Default: 3600) The lifetime of the IPsec connection in kilobytes. (Default: 0) Specifies if the IPsec tunnel should use Tunnel or Transport mode. (Default: Tunnel) Certificate or Pre-shared key. (Default: PSK) Selects the Pre-shared key to use with this IPsec Tunnel. 104

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166

Name
Specifies a symbolic name for the interface. (Identifier)
Equivalent
Specifies if the interfaces should be considered security equivalent, that means
that if enabled the interface group can be used as a destination interface in rules
where connections might need to be moved between the two interfaces. (Default:
No)
Members
Specifies the interfaces that are included in the interface group.
Comments
Text describing the current object. (Optional)
3.24.5. IPSecTunnel
Description
An IPsec tunnel item is used to define IPsec endpoint and will appear as a logical interface in the
system.
Properties
Index
The index of the object, starting at 1. (Identifier)
Name
Specifies a symbolic name for the interface.
LocalNetwork
The network on "this side" of the IPsec tunnel. The IPsec tun-
nel will be established between this network and the remote
network.
RemoteNetwork
The network connected to the remote gateway. The IPsec tun-
nel will be established between the local network and this net-
work.
RemoteEndpoint
Specifies the IP address of the remote endpoint. This is the
address the security gateway will establish the IPsec tunnel
to. It also dictates from where inbound IPsec tunnels are al-
lowed. (Optional)
IKEConfigModePool
Selects
IKE
Config
Mode
Pool
to
use
for
the
tunnel.
(Optional)
IKEAlgorithms
Specifies the IKE Proposal list used with the tunnel.
IPSecAlgorithms
Specifies the IPsec Proposal list used with the tunnel.
IKELifeTimeSeconds
The lifetime of the IKE connection in seconds. Whenever it
expires, a new phase-1 exchange will be performed. (Default:
28800)
IPSecLifeTimeSeconds
The lifetime of the IPsec connection in seconds. Whenever
it's exceeded, a re-key will be initiated, providing new IPsec
encryption and authentication session keys. (Default: 3600)
IPSecLifeTimeKilobytes
The lifetime of the IPsec connection in kilobytes. (Default: 0)
EncapsulationMode
Specifies if the IPsec tunnel should use Tunnel or Transport
mode. (Default: Tunnel)
AuthMethod
Certificate or Pre-shared key. (Default: PSK)
PSK
Selects the Pre-shared key to use with this IPsec Tunnel.
3.24.5. IPSecTunnel
Chapter 3. Configuration Reference
104