VPN Mode Configuration Commands
216
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
Command example:
SRX5308>
vpn ipsec ikepolicy configure SRX-to-Paris
vpn-config[ike-policy]>
enable_mode_config N
vpn-config[ike-policy]>
direction_type Both
vpn-config[ike-policy]>
exchange_mode Main
vpn-config[ike-policy]>
ip_version ipv4
vpn-config[ike-policy]>
select_local_gateway WAN1
vpn-config[ike-policy]>
local_ident_type Local_Wan_IP
vpn-config[ike-policy]>
local_identifier 10.139.54.228
vpn-config[ike-policy]>
remote_ident_type Remote_Wan_IP
vpn-config[ike-policy]>
remote_identifier 10.112.71.154
vpn-config[ike-policy]>
encryption_algorithm 3DES
vpn-config[ike-policy]>
auth_algorithm SHA-1
vpn-config[ike-policy]>
auth_method Pre_shared_key
vpn-config[ike-policy]>
pre_shared_key 3Tg67!JXL0Oo?
vpn-config[ike-policy]>
dh_group Group2_1024_bit
vpn-config[ike-policy]>
lifetime 28800
vpn-config[ike-policy]>
enable_dead_peer_detection Y
vpn-config[ike-policy]>
detection_period 20
vpn-config[ike-policy]>
reconnect_failure_count 3
vpn-config[ike-policy]>
extended_authentication EdgeDevice
vpn-config[ike-policy]>
extended_authentication_type RadiusChap
vpn-config[ike-policy]>
save
Related show command: show vpn ipsec ikepolicy setup
vpn ipsec ikepolicy delete <ike policy name>
This command deletes an IKE policy by specifying the name of the IKE policy.
Related show command: show vpn ipsec ikepolicy setup
IPSec VPN Policy Commands
vpn ipsec vpnpolicy configure <vpn policy name>
This command configures a new or existing auto IPSec VPN policy or manual IPSec VPN
policy. After you have issued the vpn ipsec vpnpolicy configure command to specify the
name of a new or existing VPN policy, you enter the vpn-config [vpn-policy] mode, and then
you can configure one keyword and associated parameter or associated keyword or
Format vpn ipsec ikepolicy delete <ike policy name>
Mode vpn