D-Link DFL-800 CLI Guide - Page 105

Enable or disable NAT traversal. Default: OnIfNeeded

Page 105 highlights

3.24.5. IPSecTunnel LocalIDType LocalIDValue GatewayCertificate RootCertificates IDList XAuth XAuthUsername XAuthPassword DHCPOverIPSec AddRouteToRemoteNet PlaintextMTU OriginatorIPType OriginatorIP IKEMode DHGroup PFS PFSDHGroup SetupSAPer DeadPeerDetection NATTraversal KeepAlive KeepAliveSourceIP KeepAliveDestinationIP Metric Chapter 3. Configuration Reference Selects the type of Local ID to use. (Default: Auto) Specify the local identity of the tunnel ID. Selects the certificate the security gateway uses to authenticate itself to the other IPsec peer. Selects one or more root certificates to use with this IPsec Tunnel. Selects the identification list to use with this IPsec Tunnel. An identification list is a list of the identities that are allowed to establish a IPsec tunnel. (Optional) Off, Required for inbound or Pass to peer gateway. (Default: Off) Specifies the username to pass to the remote gateway vie IKE XAuth. Specifies the password to pass to the remote gateway vie IKE XAuth. Allow DHCP over IPsec from single-host clients. (Default: No) Dynamically add route to the remote networks when a tunnel is established. (Default: No) Specifies the size in bytes at which to fragment plaintext packets (rather than fragmenting IPsec). (Default: 1424) Specifies what IP address to use as source IP in e.g. NAT. (Default: LocalInterface) Manually specified originator IP address to use as source IP in e.g. NAT. Specifies which IKE mode to use: main or aggressive. (Default: Main) Specifies the Diffie-Hellman group to use when doing key exchanges in IKE. (Default: 2) Specifies whether PFS should be used or not. (Default: None) Specifies which Diffie-Hellman group to use with PFS. (Default: 2) Setup security association per network, host or port. (Default: Net) Enable Dead Peer Detection. (Default: Yes) Enable or disable NAT traversal. (Default: OnIfNeeded) Disabled, Auto or Manual. (Default: Disabled) Source IP address used when sending keep-alive ICMP pings. Destination IP address used when sending keep-alive ICMP pings. Specifies the metric for the auto-created route. (Default: 90) 105

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166

LocalIDType
Selects the type of Local ID to use. (Default: Auto)
LocalIDValue
Specify the local identity of the tunnel ID.
GatewayCertificate
Selects the certificate the security gateway uses to authentic-
ate itself to the other IPsec peer.
RootCertificates
Selects one or more root certificates to use with this IPsec
Tunnel.
IDList
Selects the identification list to use with this IPsec Tunnel. An
identification list is a list of the identities that are allowed to
establish a IPsec tunnel. (Optional)
XAuth
Off, Required for inbound or Pass to peer gateway. (Default:
Off)
XAuthUsername
Specifies the username to pass to the remote gateway vie IKE
XAuth.
XAuthPassword
Specifies the password to pass to the remote gateway vie IKE
XAuth.
DHCPOverIPSec
Allow DHCP over IPsec from single-host clients. (Default:
No)
AddRouteToRemoteNet
Dynamically add route to the remote networks when a tunnel
is established. (Default: No)
PlaintextMTU
Specifies the size in bytes at which to fragment plaintext
packets (rather than fragmenting IPsec). (Default: 1424)
OriginatorIPType
Specifies what IP address to use as source IP in e.g. NAT.
(Default: LocalInterface)
OriginatorIP
Manually specified originator IP address to use as source IP
in e.g. NAT.
IKEMode
Specifies
which
IKE
mode
to
use:
main
or
aggressive.
(Default: Main)
DHGroup
Specifies the Diffie-Hellman group to use when doing key ex-
changes in IKE. (Default: 2)
PFS
Specifies whether PFS should be used or not. (Default: None)
PFSDHGroup
Specifies which Diffie-Hellman group to use with PFS.
(Default: 2)
SetupSAPer
Setup security association per network, host or port. (Default:
Net)
DeadPeerDetection
Enable Dead Peer Detection. (Default: Yes)
NATTraversal
Enable or disable NAT traversal. (Default: OnIfNeeded)
KeepAlive
Disabled, Auto or Manual. (Default: Disabled)
KeepAliveSourceIP
Source IP address used when sending keep-alive ICMP pings.
KeepAliveDestinationIP
Destination IP address used when sending keep-alive ICMP
pings.
Metric
Specifies the metric for the auto-created route. (Default: 90)
3.24.5. IPSecTunnel
Chapter 3. Configuration Reference
105