Motorola WS-2000-SME-WW CLI Guide - Page 188

Esp-auth, Aes128, Aes192, Aes256

Page 188 highlights

3-152 WS2000 Wireless Switch System Reference Guide authkey Sets the AH authentication key (if SPD type is Manual) for tunnel (1 to 13 characters) with the direction set to IN or OUT, and the manual authentication key set to . (The key size is 32 hex characters for MD5, and 40 hex characters for SHA1). enctype Sets the Encryption type for SPD (1 to 13 characters) to (one of None, ESP, or ESP-AUTH). encalgo Sets the Encryption Algorithm for SPD (1 to 13 characters) to (one of DES, 3DES, AES128, AES192, or AES256). espauthalgo Sets ESP Authentication Algorithm for SPD to (one of MD5 or SHA1). enckey Sets the Manual Encryption Key in ASCII for SPD and direction (IN or OUT) to the key . The size of the key depends on the encryption algorithm. - 16 hex chars for DES - 48 hex chars for 3DES - 32 hex chars for AES128 - 48 hex chars for AES192 - 64 hex chars for AES256 espauthkey Sets Manual ESP Authentication Key for SPD (1 to 13 characters) either for direction (IN or OUT) to , an ASCII string of hex characters. If authalgo is set to MD5, the provide 32 hex characters. If authalgo is set to SHA1, provide 40 hex characters. spi Sets the direction (IN(bound) or OUT(bound)) SPI for (AUTH (Manual Authentication) or ESP) for SPD (1 to 13 characters) to (a hex value more than 0xFF). localgw Sets the Local WAN IP to (a.b.c.d) for a SPI (1 to 13 characters). The local WAN IP (local gateway) can be set to 0.0.0.0 for a DHCP client. Any IP address obtained from the DHCP server is then used to initiate the VPN tunnel. The VPN peer must set it's Remote Gateway address to 0.0.0.0 to indicate an IP value of ANY and shall operate as a responder only. usepfs Enables or disables Perfect Forward Secrecy for SPD (1 to 13 characters). salife ipsecdel Enables the deletion of IPSEC SA when IKE SA is deleted for the tunnel named (1 to 13 characters). auto-initiation Enables / disables auto-initiation by WS2000 for the tunnel named (1 to 13 characters). auto-initiate-interval Sets the time duration between two consecutive auto-initiation attempts. This time duration is in seconds. Example admin(network.wan.vpn)>list Bob Detail listing of VPN entry: Name : Bob Local Subnet : 1

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452

3-152
WS2000 Wireless Switch System Reference Guide
Example
admin(network.wan.vpn)>list Bob
-------------------------------------------------------------------------
Detail listing of VPN entry:
------------------------------------------------------------------------
Name
: Bob
Local Subnet
: 1
authkey <name>
<direction> <authkey>
Sets the AH authentication key (if SPD type is Manual) for tunnel
<name>
(
1
to
13
characters) with the direction <direction> set to
IN
or
OUT
, and the manual
authentication key set to
<authkey>
. (The key size is 32 hex characters for MD5,
and 40 hex characters for SHA1).
enctype <name>
<enctype>
Sets the Encryption type for SPD
<name>
(
1
to
13
characters) to
<enctype>
(one
of
None
,
ESP
, or
ESP-AUTH
).
encalgo <name>
<encalgo>
Sets the Encryption Algorithm for SPD
<name>
(
1
to
13
characters) to
<encalgo>
(one of
DES
,
3DES
,
AES128
,
AES192
, or
AES256
).
espauthalgo <name>
<espauthalgo>
Sets ESP Authentication Algorithm for SPD
<name>
to
<espauthalgo>
(one of
MD5
or
SHA1
).
enckey <name>
<direction> <enckey>
Sets the Manual Encryption Key in ASCII for SPD
<name>
and direction
<direction>
(
IN
or
OUT)
to the key
<enckey>
. The size of the key depends on
the encryption algorithm.
- 16 hex chars for DES
- 48 hex chars for 3DES
- 32 hex chars for AES128
- 48 hex chars for AES192
- 64 hex chars for AES256
espauthkey <name>
<direction>
<espauthkey>
Sets Manual ESP Authentication Key for SPD
<name>
(
1
to
13
characters)
either
for direction
<direction>
(
IN
or
OUT)
to
<espauthkey>
, an ASCII string of hex
characters. If authalgo is set to
MD5
, the provide 32 hex characters. If authalgo is
set to
SHA1
, provide 40 hex characters.
spi <name> <algo>
<direction> <spi>
Sets the direction
<direction>
(IN
(bound) or
OUT
(bound)) SPI for
<algo>
(AUTH
(Manual Authentication) or
ESP
) for SPD
<name>
(
1
to
13
characters) to
<spi>
(a
hex value more than 0xFF).
localgw <name> <ip>
Sets the Local WAN IP to
<ip>
(a.b.c.d) for a SPI
<name>
(
1
to
13
characters).
The local WAN IP (local gateway) can be set to 0.0.0.0 for a DHCP client. Any IP
address obtained from the DHCP server is then used to initiate the VPN tunnel.
The VPN peer must set it’s Remote Gateway address to 0.0.0.0 to indicate an IP
value of ANY and shall operate as a responder only.
usepfs <name>
<usepfs>
Enables or disables Perfect Forward Secrecy for SPD
<name>
(
1
to
13
characters).
salife <name> <life
time>
Sets SA life time to
<lifetime>
seconds (minimum 300).
ipsecdel <name>
<mode>
Enables the deletion of IPSEC SA when IKE SA is deleted for the tunnel named
<name>
(
1
to
13
characters).
auto-initiation <name>
<mode>
Enables / disables auto-initiation by WS2000 for the tunnel named
<name>
(
1
to
13
characters).
auto-initiate-interval
<time>
Sets the time duration between two consecutive auto-initiation attempts. This
time duration is in seconds.