Fortinet white logo
Fortinet white logo

CLI Reference

7.2.1

config vpn ipsec phase2-interface

config vpn ipsec phase2-interface

Configure VPN autokey tunnel.

Syntax

config vpn ipsec phase2-interface
    edit <name>
        set dst-end-ip {ipv4-address-any}
        set dst-name {string}
        set dst-start-ip {ipv4-address-any}
        set dst-subnet {ipv4-classnet-any}
        set keylifeseconds {integer}
        set phase1name {string}
        set proposal {option1}, {option2}, ...
        set src-addr-type [subnet|range|...]
        set src-end-ip {ipv4-address-any}
        set src-name {string}
        set src-start-ip {ipv4-address-any}
        set src-subnet {ipv4-classnet-any}
    next
end

config vpn ipsec phase2-interface

Parameter

Description

Type

Size

Default

dst-end-ip

Remote proxy ID IPv4 end.

ipv4-address-any

Not Specified

0.0.0.0

dst-name

Remote proxy ID name.

string

Maximum length: 79

dst-start-ip

Remote proxy ID IPv4 start.

ipv4-address-any

Not Specified

0.0.0.0

dst-subnet

Remote proxy ID IPv4 subnet.

ipv4-classnet-any

Not Specified

0.0.0.0 0.0.0.0

keylifeseconds

Phase2 key life in time in seconds.

integer

Minimum value: 120 Maximum value: 172800

43200

phase1name

Phase 1 determines the options required for phase 2.

string

Maximum length: 15

proposal

Phase2 proposal.

option

-

aes128-sha1 aes256-sha1 aes128-sha256 aes256-sha256 aes128gcm aes256gcm chacha20poly1305

Option

Description

aes128-sha1

aes128-sha1

aes128-sha256

aes128-sha256

aes128-sha384

aes128-sha384

aes128-sha512

aes128-sha512

aes192-sha1

aes192-sha1

aes192-sha256

aes192-sha256

aes192-sha384

aes192-sha384

aes192-sha512

aes192-sha512

aes256-sha1

aes256-sha1

aes256-sha256

aes256-sha256

aes256-sha384

aes256-sha384

aes256-sha512

aes256-sha512

aes128gcm

aes128gcm

aes256gcm

aes256gcm

chacha20poly1305

chacha20poly1305

src-addr-type

Local proxy ID type.

option

-

subnet

Option

Description

subnet

IPv4 subnet.

range

IPv4 range.

ip

IPv4 IP.

name

IPv4 firewall address or group name.

subnet6

IPv6 subnet.

range6

IPv6 range.

ip6

IPv6 IP.

name6

IPv6 firewall address or group name.

src-end-ip

Local proxy ID end.

ipv4-address-any

Not Specified

0.0.0.0

src-name

Local proxy ID name.

string

Maximum length: 79

src-start-ip

Local proxy ID start.

ipv4-address-any

Not Specified

0.0.0.0

src-subnet

Local proxy ID subnet.

ipv4-classnet-any

Not Specified

0.0.0.0 0.0.0.0

config vpn ipsec phase2-interface

config vpn ipsec phase2-interface

Configure VPN autokey tunnel.

Syntax

config vpn ipsec phase2-interface
    edit <name>
        set dst-end-ip {ipv4-address-any}
        set dst-name {string}
        set dst-start-ip {ipv4-address-any}
        set dst-subnet {ipv4-classnet-any}
        set keylifeseconds {integer}
        set phase1name {string}
        set proposal {option1}, {option2}, ...
        set src-addr-type [subnet|range|...]
        set src-end-ip {ipv4-address-any}
        set src-name {string}
        set src-start-ip {ipv4-address-any}
        set src-subnet {ipv4-classnet-any}
    next
end

config vpn ipsec phase2-interface

Parameter

Description

Type

Size

Default

dst-end-ip

Remote proxy ID IPv4 end.

ipv4-address-any

Not Specified

0.0.0.0

dst-name

Remote proxy ID name.

string

Maximum length: 79

dst-start-ip

Remote proxy ID IPv4 start.

ipv4-address-any

Not Specified

0.0.0.0

dst-subnet

Remote proxy ID IPv4 subnet.

ipv4-classnet-any

Not Specified

0.0.0.0 0.0.0.0

keylifeseconds

Phase2 key life in time in seconds.

integer

Minimum value: 120 Maximum value: 172800

43200

phase1name

Phase 1 determines the options required for phase 2.

string

Maximum length: 15

proposal

Phase2 proposal.

option

-

aes128-sha1 aes256-sha1 aes128-sha256 aes256-sha256 aes128gcm aes256gcm chacha20poly1305

Option

Description

aes128-sha1

aes128-sha1

aes128-sha256

aes128-sha256

aes128-sha384

aes128-sha384

aes128-sha512

aes128-sha512

aes192-sha1

aes192-sha1

aes192-sha256

aes192-sha256

aes192-sha384

aes192-sha384

aes192-sha512

aes192-sha512

aes256-sha1

aes256-sha1

aes256-sha256

aes256-sha256

aes256-sha384

aes256-sha384

aes256-sha512

aes256-sha512

aes128gcm

aes128gcm

aes256gcm

aes256gcm

chacha20poly1305

chacha20poly1305

src-addr-type

Local proxy ID type.

option

-

subnet

Option

Description

subnet

IPv4 subnet.

range

IPv4 range.

ip

IPv4 IP.

name

IPv4 firewall address or group name.

subnet6

IPv6 subnet.

range6

IPv6 range.

ip6

IPv6 IP.

name6

IPv6 firewall address or group name.

src-end-ip

Local proxy ID end.

ipv4-address-any

Not Specified

0.0.0.0

src-name

Local proxy ID name.

string

Maximum length: 79

src-start-ip

Local proxy ID start.

ipv4-address-any

Not Specified

0.0.0.0

src-subnet

Local proxy ID subnet.

ipv4-classnet-any

Not Specified

0.0.0.0 0.0.0.0