Unified Services Router    CLI Reference Guide 
 
72 
 
authentication method mentioned in the 
IKE SA parameters. 
auto_phase1_authe
ntication_type 
 
If userdata base is selected 
authentication done using local 
Database.If Radius  option is selected 
authentication is done using external 
radius server 
Authentication type (User 
DataBase  / Radius-PAP / Radius-
CHAP) 
auto_phase1_xauth
_password   
 
 The password can contain 
alphanumeric characters 
String, 
The password can contain 
alphanumeric characters 
auto_phase1_xauth
_username 
 
This is the unique identifier for the user, 
and can contain any alphanumeric 
characters 
This is the unique identifier for the 
user, and can contain any 
alphanumeric characters. 
Takes a hexadecimal value between 3 
and 8 characters 
Takes a hexadecimal value between 3 
and 8 characters 
manual_encryption
_algorithm   
 
The algorithm used to encrypt the data 
vpn encryption algorithm 
(None/DES/3DES/AES-128/AES-
192/AES-256/AES-CCM/AES-
GCM//TWOFISH(128/192/256)/ 
BLOWFISH/CAST128) 
BLOWFISH and CAST128 are variable 
length algorithms, and so the key length 
field is required when using either of 
these encryption types. For 
BLOWFISH, the Key Length must be 
between 40 and 448 and it must be a 
multiple of 8. For CAST128, the Key 
Length must be between 40 and 128 
and it must be a multiple of 8. 
Encryption key of the inbound policy. 
The length of the key depends on the 
algorithm chosen 
manual_encryption
_key_out 
 
cryption key of the outbound policy. The 
length of the key depends on the 
algorithm chosen. 
manual_authentica
tion_algorithm  
 
Algorithm used to verify the integrity of 
the data. 
vpn authentication algorithm 
(MD5/SHA-1/SHA2-256/SHA2-
384/SHA2-512) 
manual_authentica
tion_key_in  
 
This is the integrity key (for ESP with 
Integrity-mode) for the inbound policy 
and depends on the algorithm chosen 
manual_authentica
tion_key_out   
 
This is the integrity key (for ESP with 
Integrity-mode) for the outbound policy 
and depends on the algorithm chosen 
It is the interval after which the Security 
Association becomes invalid 
salifetime Unsigned integer