Fortinet white logo
Fortinet white logo

CLI Reference

config phase2-interface

config phase2-interface

Description: Configure VPN autokey tunnel.

config phase2-interface

edit <name>
			set *phase1name
			set pfs [enable | disable]
			set dhgrp [1 | 2 | 5 | 14]
			set keylife-type [seconds | kbs]
			set keylifeseconds [120 – 172800]
			set encapsulation [tunnel-mode | transport-mode]
			set protocol [0 – 255]
			set src-addr-type [subnet | range | ip | name]
			set src-subnet {ipv4-subnet}
			set *src-start-ip {ipv4-address} *available when src-addr-type is range and ip
			set *src-end-ip {ipv4-address} *available when src-addr-type is range
			set *src-name {string} *available when src-addr-type is name
			set src-port [0 – 65535]
			set dst-addr-type [subnet | range | ip | name]
			set dst-subnet {ipv4-subnet}
			set *dst-start-ip {ipv4-address} *available when dst-addr-type is range and ip
			set *dst-end-ip {ipv4-address} *available when dst-addr-type is range
			set *dst-name {string} *available when dst-addr-type is name
			set dst-port [0 – 65535]
			unset
			next
			show
			abort
			end
		delete <name>
		purge
		show
		end
	show
	end
Sample command:
FX201E5919000057 (phase2-interface) # show
config vpn ipsec phase2-interface
    edit phase2_1
        set phase1name phase1_1
        set proposal aes128-sha1 aes256-sha1 3des-sha1 aes128-sha256 aes256-sha256 3des-sha256
        set pfs enable
        set dhgrp 14 5
        set keylife-type seconds
        set keylifeseconds 43200
        set encapsulation tunnel-mode
        set protocol 0
        set src-addr-type subnet
        set src-subnet 0.0.0.0/0
        set src-port 0
        set dst-addr-type subnet
        set dst-subnet 107.204.148.0/24
        set dst-port 234
    next
end
Parameter Description Type Size Default
phase1name Phase 1 name (which determines the options required for phase 2). string - none
proposal Phase 2 proposal. option -

aes128-sha1

aes256-sha1

3des-sha1

aes128-sha256

aes256-sha256

3des-sha256

pfs Status of the PFS feature. option - enable

Option

Description

enable Enable PFS.
disable Disable PFS.
dhgrp Phase 2 DH group. option - 14, 5
Option Description
1
2
5
14
keylife-type Keylife type option - seconds
Option Description
seconds Seconds.
kbs Kbs.

keylifeseconds

Phase 2 key life in seconds.

integer

120 – 172800

43200

keylifekbs

Phase 2 key life in the number of bytes of traffic.

integer

5120 - 4294967295

5120

encapsulation

ESP encapsulation mode.

option

-

tunnel-mode

Option Description
tunnel-mode Tunnel mode.
transport-mode Transport mode.

protocol

Quick mode protocol selector.

integer

1 - 255

0

src-addr-type

Local proxy ID type.

option

-

subnet

Option Description
subnet IPv4 subnet.
range IPv4 range.
ip IPv4 IP.
name IPv4 network address name.

src-subnet

Local proxy ID subnet.

IPv4 address

-

0.0.0.0/0

src-port

Quick mode source port.

integer

1 - 65535, or 0 for all

0

dst-addr-type

Remote proxy ID type.

option

-

subnet

Option Description
subnet IPv4 subnet.
range IPv4 range.
ip IPv4 IP.

name

IPv4 network address name.

dst-subnet

Remote proxy ID subnet.

IPv4 address

-

0.0.0.0/0

dst-port

Quick mode source port.

integer

1 - 65535, or 0 for all

0

src-start-ip

Local proxy ID start.

IPv4 address

-

none

src-end-ip

Local proxy ID end.

IPv4 address

-

none

dst-start-ip

Remote proxy ID start.

IPv4 address

-

none

dst-end-ip

Remote proxy ID end

IPv4 address

-

none

src-name

Local proxy ID name.

string

-

none

dst-name

Remote proxy ID name.

string

-

none

config phase2-interface

config phase2-interface

Description: Configure VPN autokey tunnel.

config phase2-interface

edit <name>
			set *phase1name
			set pfs [enable | disable]
			set dhgrp [1 | 2 | 5 | 14]
			set keylife-type [seconds | kbs]
			set keylifeseconds [120 – 172800]
			set encapsulation [tunnel-mode | transport-mode]
			set protocol [0 – 255]
			set src-addr-type [subnet | range | ip | name]
			set src-subnet {ipv4-subnet}
			set *src-start-ip {ipv4-address} *available when src-addr-type is range and ip
			set *src-end-ip {ipv4-address} *available when src-addr-type is range
			set *src-name {string} *available when src-addr-type is name
			set src-port [0 – 65535]
			set dst-addr-type [subnet | range | ip | name]
			set dst-subnet {ipv4-subnet}
			set *dst-start-ip {ipv4-address} *available when dst-addr-type is range and ip
			set *dst-end-ip {ipv4-address} *available when dst-addr-type is range
			set *dst-name {string} *available when dst-addr-type is name
			set dst-port [0 – 65535]
			unset
			next
			show
			abort
			end
		delete <name>
		purge
		show
		end
	show
	end
Sample command:
FX201E5919000057 (phase2-interface) # show
config vpn ipsec phase2-interface
    edit phase2_1
        set phase1name phase1_1
        set proposal aes128-sha1 aes256-sha1 3des-sha1 aes128-sha256 aes256-sha256 3des-sha256
        set pfs enable
        set dhgrp 14 5
        set keylife-type seconds
        set keylifeseconds 43200
        set encapsulation tunnel-mode
        set protocol 0
        set src-addr-type subnet
        set src-subnet 0.0.0.0/0
        set src-port 0
        set dst-addr-type subnet
        set dst-subnet 107.204.148.0/24
        set dst-port 234
    next
end
Parameter Description Type Size Default
phase1name Phase 1 name (which determines the options required for phase 2). string - none
proposal Phase 2 proposal. option -

aes128-sha1

aes256-sha1

3des-sha1

aes128-sha256

aes256-sha256

3des-sha256

pfs Status of the PFS feature. option - enable

Option

Description

enable Enable PFS.
disable Disable PFS.
dhgrp Phase 2 DH group. option - 14, 5
Option Description
1
2
5
14
keylife-type Keylife type option - seconds
Option Description
seconds Seconds.
kbs Kbs.

keylifeseconds

Phase 2 key life in seconds.

integer

120 – 172800

43200

keylifekbs

Phase 2 key life in the number of bytes of traffic.

integer

5120 - 4294967295

5120

encapsulation

ESP encapsulation mode.

option

-

tunnel-mode

Option Description
tunnel-mode Tunnel mode.
transport-mode Transport mode.

protocol

Quick mode protocol selector.

integer

1 - 255

0

src-addr-type

Local proxy ID type.

option

-

subnet

Option Description
subnet IPv4 subnet.
range IPv4 range.
ip IPv4 IP.
name IPv4 network address name.

src-subnet

Local proxy ID subnet.

IPv4 address

-

0.0.0.0/0

src-port

Quick mode source port.

integer

1 - 65535, or 0 for all

0

dst-addr-type

Remote proxy ID type.

option

-

subnet

Option Description
subnet IPv4 subnet.
range IPv4 range.
ip IPv4 IP.

name

IPv4 network address name.

dst-subnet

Remote proxy ID subnet.

IPv4 address

-

0.0.0.0/0

dst-port

Quick mode source port.

integer

1 - 65535, or 0 for all

0

src-start-ip

Local proxy ID start.

IPv4 address

-

none

src-end-ip

Local proxy ID end.

IPv4 address

-

none

dst-start-ip

Remote proxy ID start.

IPv4 address

-

none

dst-end-ip

Remote proxy ID end

IPv4 address

-

none

src-name

Local proxy ID name.

string

-

none

dst-name

Remote proxy ID name.

string

-

none