06.02.2014 Views

User's Guide Command Line Interface - QLogic

User's Guide Command Line Interface - QLogic

User's Guide Command Line Interface - QLogic

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

3–Network Configuration<br />

Managing IP Security<br />

Creating an IKE Policy<br />

To create an IKE peer, enter the Ike Policy Create command as shown in the<br />

following example:<br />

SANbox (admin-ipsec) #> ike policy create policy_2<br />

A list of attributes with formatting will follow.<br />

Enter a value or simply press the ENTER key to skip specifying a value.<br />

If you wish to terminate this process before reaching the end of the list<br />

press 'q' or 'Q' and the ENTER key to do so.<br />

Required attributes are preceded by an asterisk.<br />

Value (press ENTER to not specify value, 'q' to quit):<br />

Description (string, max=127 chars, N=None) : Policy 2<br />

*Mode (1=transport, 2=tunnel) : 1<br />

*LocalAddress (IPv4, IPv6 Address or keyword 'All' : 10.0.0.3<br />

LocalPort (decimal value, 0-65535 or keyword 'All' : 1234<br />

RemotePort (decimal value, 0-65535 or keyword 'All' : 0<br />

*Peer (string, max=32 chars) : peer_1<br />

*Protocol<br />

(decimal value, 0-255, or keyword)<br />

0=NotSpecified<br />

Allowed keywords<br />

icmp, icmp6, ip4, tcp, udp or any : udp<br />

Action (1=ipsec) : 1<br />

ProtectionDesired (select one, transport-mode only)<br />

1=esp Encapsulating Security Payload : 1<br />

LifetimeChild (decimal value, 900-86400 seconds) : 3600<br />

RekeyChild (True / False) : True<br />

*Encryption<br />

(select one or more encryption algorithms)<br />

1=3des_cbc<br />

2=aes_cbc_128<br />

3=aes_cbc_192<br />

4=aes_cbc_256<br />

5=null : 1<br />

Integrity<br />

(select one or more integrity algorithms)<br />

1=md5_96<br />

2=sha1_96<br />

3=sha2_256<br />

4=aes_xcbc_96<br />

or the keyword 'None' : 1 2 3<br />

DHGroup<br />

(select one or more Diffie-Hellman Groups)<br />

1, 2, 5, 14, 24 or the keyword 'None' : 1 5<br />

Restrict (True / False) : True<br />

The IKE policy has been created.<br />

This configuration must be saved with the 'ipsec save' command<br />

before it can take effect, or to discard this configuration<br />

use the 'ipsec cancel' command.<br />

SANbox (admin-ipsec) #> ipsec save<br />

3-24 59263-02 B

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!