config phase2-interface
Description: Configure VPN autokey tunnel.
config phase2-interface
edit <name>
set *phase1name
set pfs [enable | disable]
set dhgrp [1 | 2 | 5 | 14]
set keylife-type [seconds | kbs]
set keylifeseconds [120 – 172800]
set encapsulation [tunnel-mode | transport-mode]
set protocol [0 – 255]
set src-addr-type [subnet | range | ip | name]
set src-subnet {ipv4-subnet}
set *src-start-ip {ipv4-address} *available when src-addr-type is range and ip
set *src-end-ip {ipv4-address} *available when src-addr-type is range
set *src-name {string} *available when src-addr-type is name
set src-port [0 – 65535]
set dst-addr-type [subnet | range | ip | name]
set dst-subnet {ipv4-subnet}
set *dst-start-ip {ipv4-address} *available when dst-addr-type is range and ip
set *dst-end-ip {ipv4-address} *available when dst-addr-type is range
set *dst-name {string} *available when dst-addr-type is name
set dst-port [0 – 65535]
unset
next
show
abort
end
delete <name>
purge
show
end
show
end
Sample command:
FX201E5919000057 (phase2-interface) # show
config vpn ipsec phase2-interface
edit phase2_1
set phase1name phase1_1
set proposal aes128-sha1 aes256-sha1 3des-sha1 aes128-sha256 aes256-sha256 3des-sha256
set pfs enable
set dhgrp 14 5
set keylife-type seconds
set keylifeseconds 43200
set encapsulation tunnel-mode
set protocol 0
set src-addr-type subnet
set src-subnet 0.0.0.0/0
set src-port 0
set dst-addr-type subnet
set dst-subnet 107.204.148.0/24
set dst-port 234
next
end
| Parameter | Description | Type | Size | Default | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| phase1name | Phase 1 name (which determines the options required for phase 2). | string | - | none | ||||||||||
| proposal | Phase 2 proposal. | option | - |
aes128-sha1 aes256-sha1 3des-sha1 aes128-sha256 aes256-sha256 3des-sha256 |
||||||||||
| pfs | Status of the PFS feature. | option | - | enable | ||||||||||
|
||||||||||||||
| dhgrp | Phase 2 DH group. | option | - | 14, 5 | ||||||||||
|
||||||||||||||
| keylife-type | Keylife type | option | - | seconds | ||||||||||
|
||||||||||||||
|
keylifeseconds |
Phase 2 key life in seconds. |
integer |
120 – 172800 |
43200 |
||||||||||
|
keylifekbs |
Phase 2 key life in the number of bytes of traffic. |
integer |
5120 - 4294967295 |
5120 |
||||||||||
|
encapsulation |
ESP encapsulation mode. |
option |
- |
tunnel-mode |
||||||||||
|
|
|
|||||||||||||
|
protocol |
Quick mode protocol selector. |
integer |
1 - 255 |
0 |
||||||||||
|
src-addr-type |
Local proxy ID type. |
option |
- |
subnet |
||||||||||
|
|
|
|||||||||||||
|
src-subnet |
Local proxy ID subnet. |
IPv4 address |
- |
0.0.0.0/0 |
||||||||||
|
src-port |
Quick mode source port. |
integer |
1 - 65535, or 0 for all |
0 |
||||||||||
|
dst-addr-type |
Remote proxy ID type. |
option |
- |
subnet |
||||||||||
|
|
|
|||||||||||||
|
dst-subnet |
Remote proxy ID subnet. |
IPv4 address |
- |
0.0.0.0/0 |
||||||||||
|
dst-port |
Quick mode source port. |
integer |
1 - 65535, or 0 for all |
0 |
||||||||||
|
src-start-ip |
Local proxy ID start. |
IPv4 address |
- |
none |
||||||||||
|
src-end-ip |
Local proxy ID end. |
IPv4 address |
- |
none |
||||||||||
|
dst-start-ip |
Remote proxy ID start. |
IPv4 address |
- |
none |
||||||||||
|
dst-end-ip |
Remote proxy ID end |
IPv4 address |
- |
none |
||||||||||
|
src-name |
Local proxy ID name. |
string |
- |
none |
||||||||||
|
dst-name |
Remote proxy ID name. |
string |
- |
none |
||||||||||