ZyXEL Communications ZYWALL 1050 - V2.00 EDITION 1 Betriebsanweisung Seite 140

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 386
  • Inhaltsverzeichnis
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 139
Chapter 16 IPSec VPN
ZyWALL (ZLD) CLI Reference Guide
140
scenario {site-to-site-static|site-to-
site-dynamic|remote-access-server|remote-
access-client}
Select the scenario that best describes your
intended VPN connection.
Site-to-site: The remote IPSec router has a
static IP address or a domain name. This ZyWALL
can initiate the VPN tunnel.
site-to-site-dynamic: The remote IPSec
router has a dynamic IP address. Only the remote
IPSec router can initiate the VPN tunnel.
remote-access-server: Allow incoming
connections from IPSec VPN clients. The clients
have dynamic IP addresses and are also known as
dial-in users. Only the clients can initiate the VPN
tunnel.
remote-access-client: Choose this to
connect to an IPSec server. This ZyWALL is the
client (dial-in user) and can initiate the VPN tunnel.
set security-association lifetime seconds
<180..3000000>
Sets the IPSec SA life time.
set pfs {group1 | group2 | group5 | none} Enables Perfect Forward Secrecy group.
local-policy address_name Sets the address object for the local policy (local
network).
remote-policy address_name Sets the address object for the remote policy
(remote network).
[no] policy-enforcement Drops traffic whose source and destination IP
addresses do not match the local and remote
policy. This makes the IPSec SA more secure. The
no command allows traffic whose source and
destination IP addresses do not match the local
and remote policy.
Note: You must allow traffic whose source
and destination IP addresses do
not match the local and remote
policy, if you want to use the IPSec
SA in a VPN concentrator.
[no] nail-up Automatically re-negotiates the SA as needed. The
no command does not.
[no] replay-detection Enables replay detection. The
no command
disables it.
[no] netbios-broadcast Enables NetBIOS broadcasts through the IPSec
SA. The no command disables NetBIOS
broadcasts through the IPSec SA.
[no] out-snat activate Enables out-bound traffic SNAT over IPSec. The
no command disables out-bound traffic SNAT over
IPSec.
out-snat source address_name destination
address_name snat address_name
Configures out-bound traffic SNAT in the IPSec SA.
[no] in-snat activate Enables in-bound traffic SNAT in the IPSec SA.
The
no command disables in-bound traffic SNAT in
the IPSec SA.
Table 69 crypto Commands: IPSec SAs (continued)
COMMAND DESCRIPTION
Seitenansicht 139
1 2 ... 135 136 137 138 139 140 141 142 143 144 145 ... 385 386

Kommentare zu diesen Handbüchern

Keine Kommentare