CLI Guide - WatchGuard Technologies

CLI Guide - WatchGuard Technologies CLI Guide - WatchGuard Technologies

watchguard.com
from watchguard.com More from this publisher
25.06.2013 Views

CHAPTER 3: Configuration Mode Commands preceding arguments, the following values are options you can apply: Option Description g1 and g2 the two Diffie-Hellman group options. des|3des represent two encryption algorithm options. md5|sha represent two other encryption algorithm options. Lifetimeminutes/hours represent a key lifetime setting, measured in time. Lifesize-KB/MB represent a key lifetime, measured in kilo- or megabytes. Example WG(config-ike)#action my_act -main \ (line break) –rsa {g2 3des md5 10hr 100MB} {g1 des sha 45min} \ –dss {g2 3des sha 8hr} policy command (configure IKE level) WG#config WG(config)#ike WG(config-ike)#policy \ -action \ -peer \ [-local {} [-preshared ] \ [-position ] Effect Records a new IKE policy, including actions. 80 WatchGuard Vclass 5.1

Second level configuration mode commands Arguments This argument records a brief, descriptive name for this policy. < * |peer_address> This argument notes either “any” (indicated by *) or the address group representing the peer appliance(s). -action This argument notes the name of the IKE action used by this policy. -peer | -address &| - domain \ &| -user_domain &| -X.500 \ 0] This argument specifies the means of identifying the peer appliance from these five options. You can enter “any” as the sole option or combine any of these options (and values) in this argument: Option Description represents an address group used as peer ID type. represents a domain name as the peer ID type. represents a user domain name as the peer ID type. represents X.500 as the peer ID type. [-local { This optional argument specifies which ID }] for -peer, as noted above. [-preshared This optional argument records the text of WatchGuard Command Line Interface Guide 81

CHAPTER 3: Configuration Mode Commands<br />

preceding arguments, the following values are<br />

options you can apply:<br />

Option Description<br />

g1 and g2 the two Diffie-Hellman group options.<br />

des|3des represent two encryption algorithm options.<br />

md5|sha represent two other encryption algorithm options.<br />

Lifetimeminutes/hours<br />

represent a key lifetime setting, measured in time.<br />

Lifesize-KB/MB represent a key lifetime, measured in kilo- or<br />

megabytes.<br />

Example<br />

WG(config-ike)#action my_act -main \<br />

(line break)<br />

–rsa {g2 3des md5 10hr 100MB} {g1 des<br />

sha 45min} \<br />

–dss {g2 3des sha 8hr}<br />

policy command (configure IKE level)<br />

WG#config<br />

WG(config)#ike <br />

WG(config-ike)#policy \<br />

-action<br />

\<br />

-peer \<br />

[-local<br />

{} [-preshared ]<br />

\<br />

[-position ]<br />

Effect<br />

Records a new IKE policy, including actions.<br />

80 <strong>WatchGuard</strong> Vclass 5.1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!