CLI Guide - WatchGuard Technologies

CLI Guide - WatchGuard Technologies CLI Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
25.06.2013 Views

CHAPTER 3: Configuration Mode Commands Effect Records a new IPSec action (manual key or automatic key), including one or more proposals which have been created beforehand. Arguments Type a unique name for this action. This argument determines whether this action is tunnel mode or transport mode. If you enter tunnel mode, you must then qualify it with one of the following: (1) enter "*" to indicate ANY source, (2) enter a specific peer appliance’s IP address, or (3) enter the name of an address group containing the peer IP address. -auto_key Enter this argument if this action utilizes an automatic key. Do not use the “manual–key” if using an automatic key. The following two arguments further qualify this automatic key exchange. [no] pfs_group If this action uses an automatic key, use this argument to specify which perfect forward security option (Diffie-Hellman Group 1 or 2) will be used. If none is used, you can preface this argument with “no”. […] If this action uses an automatic key, use this argument to enter the IKE proposal names (whether one or more.) -manual_key Enter this argument if this action employs a manual key. (If doing so, do not use the “auto_key” argument.) The following ten arguments (grouped 96 WatchGuard Vclass 5.1

Second level configuration mode commands around ESP and AH algorithms) qualify this manual key exchange. -esp Enter this argument if this action employs an ESP protocol for the manual key. Use this argument to enter a unique number that represents the SPI of this appliance. The number should be between 256 and 65535. Use this argument to enter a different, unique number that represents the SPI of the peer security appliance. The number should be between 256 and 65535. Use this argument to pick either DES or 3DES encryption algorithms. This argument will contain the actual manual key text, noted in ASCII or hexadecimal notation. -ah Enter this argument if this action employs an AH protocol for the manual key. Use this argument to enter a unique number that represents the SPI of this appliance. The number should be between 256 and 65535. Use this argument to enter a different, unique number that represents the SPI of the peer security WatchGuard Command Line Interface Guide 97

CHAPTER 3: Configuration Mode Commands<br />

Effect<br />

Records a new IPSec action (manual key or<br />

automatic key), including one or more proposals<br />

which have been created beforehand.<br />

Arguments<br />

<br />

Type a unique name for this action.<br />

<br />

This argument determines whether this action is<br />

tunnel mode or transport mode.<br />

<br />

If you enter tunnel mode, you must then qualify it<br />

with one of the following: (1) enter "*" to indicate<br />

ANY source, (2) enter a specific peer appliance’s IP<br />

address, or (3) enter the name of an address group<br />

containing the peer IP address.<br />

-auto_key<br />

Enter this argument if this action utilizes an<br />

automatic key. Do not use the “manual–key” if<br />

using an automatic key.<br />

The following two arguments further qualify this<br />

automatic key exchange.<br />

[no] pfs_group <br />

If this action uses an automatic key, use this<br />

argument to specify which perfect forward security<br />

option (Diffie-Hellman Group 1 or 2) will be used.<br />

If none is used, you can preface this argument with<br />

“no”.<br />

[…]<br />

If this action uses an automatic key, use this<br />

argument to enter the IKE proposal names<br />

(whether one or more.)<br />

-manual_key<br />

Enter this argument if this action employs a<br />

manual key. (If doing so, do not use the “auto_key”<br />

argument.) The following ten arguments (grouped<br />

96 <strong>WatchGuard</strong> Vclass 5.1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!