VPN Mode Configuration Commands
210
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
vpn-config[wizard]>
enable_rollover N
vpn-config[wizard]>
remote_wan_ipaddress peer44.com
vpn-config[wizard]>
local_wan_ipaddress fe80::a8ab:bbff:fe00:2
vpn-config[wizard]>
remote_lan_ipv6address fe80::a4bb:ffdd:fe01:2
vpn-config[wizard]>
remote_lan_prefixLength 64
vpn-config[wizard]>
save
Related show command: show vpn ipsec vpnpolicy setup, show vpn ipsec ikepolicy setup, and show
vpn ipsec vpnpolicy status
To display the VPN policy configuration that the wizard created through the vpn ipsec
wizard configure command, issue the show vpn ipsec vpnpolicy setup
command:
SRX5308>
show vpn ipsec vpnpolicy setup
Status Name Type IPSec Mode Local Remote Auth Encr
_______ _________________ ___________ ___________ ______________________________________ ______________________________ _____ ____
Enabled SRX5308-to-Peer44 Auto Policy Tunnel Mode 2002:408b:36e4:a:a8ab:bbff:fe00:1 / 64 fe80::a4bb:ffdd:fe01:2 / 64 SHA-1 3DES
Enabled SRX-to-Paris Auto Policy Tunnel Mode 192.168.1.0 / 255.255.255.0 192.168.50.0 / 255.255.255.255 SHA-1 3DES
To display the IKE policy configuration that the wizard created through the vpn ipsec
wizard configure command, issue the show vpn ipsec ikepolicy setup
command:
SRX5308>
show vpn ipsec ikepolicy setup
List of IKE Policies
____________________
Name Mode Local ID Remote ID Encryption Authentication DH Group
_________________ __________ ______________________ _____________ __________ ______________ ____________
SRX5308-to-Peer44 main fe80::a8ab:bbff:fe00:2 peer44.com 3DES SHA-1 Group 2 (1024 bit)
SRX-to-Paris main 10.139.54.228 10.112.71.154 3DES SHA-1 Group 2 (1024 bit)
iphone aggressive 10.139.54.228 0.0.0.0 AES-128 SHA-1 Group 2 (1024 bit)
IPSec IKE Policy Commands
vpn ipsec ikepolicy configure <ike policy name>
This command configures a new or existing manual IPSec IKE policy. After you have issued
the vpn ipsec ikepolicy configure command to specify the name of a new or existing IKE
policy, you enter the vpn-config [ike-policy] mode, and then you can configure one keyword
and associated parameter or associated keyword or associated keyword at a time in the
order that you prefer.
Step 1 Format vpn ipsec ikepolicy configure <ike policy name>
Mode vpn