NGFW Command Line Interface Reference 167
Syntax
exchange-mode (main|aggressive)
Example
NGFW{running-ipsec-vpn-myvpn}exchange-mode aggressive
NGFW{running-ipsec-vpn-myvpn}identity
Configure local and remote IKE Identities.
Syntax
identity local ((ip-address A.B.C.D|X:X::X:X|anyLADDR)|(fqdn
HOSTNAME|anyLHOSTNAME)|(user-fqdn EMAILADDRESS|anyLEMAIL)|(asn1dn
asn1dn|anyLASNDNAME)) [remote (ip-address A.B.C.D|X:X::X:X|anyRADDR)|(fqdn
HOSTNAME|anyRHOSTNAME)|(user-fqdn EMAILADDRESS|anyREMAIL)|(asn1dn
asn1dn|anyRASNDNAME)]
Example
NGFW{running-ipsec-vpn-myvpn}identity local nearside.example.com remote
farside.example.com
NGFW{running-ipsec-vpn-myvpn}ip-compression
Enable or disable IP Compression.
Syntax
ip-compression (enable|disable)
Example
NGFW{running-ipsec-vpn-myvpn}ip-compression enable
NGFW{running-ipsec-vpn-myvpn}ip-pool
Configure IP Pool for remote VPN clients.
Syntax
ip-pool (A.B.C.D/M|X:X::X:X/M)
Example
NGFW{running-ipsec-vpn-myvpn}ip-pool 192.168.1.0/24
NGFW{running-ipsec-vpn-myvpn}key
Configure Key exchange type.
Syntax
key (ike|manual)
Example
NGFW{running-ipsec-vpn-myvpn}key ike
NGFW{running-ipsec-vpn-myvpn}nat-traversal
Enable or disable NAT Traversal mode.
Syntax
nat-traversal (enable|disable)
Commentaires sur ces manuels