VPN Mode Configuration Commands
217
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
associated keyword at a time in the order that you prefer.
Step 1 Format vpn ipsec vpnpolicy configure <vpn policy name>
Mode vpn
Step 2 Format general_policy_type {Auto-Policy | Manual-Policy}
general_ip_version {IPv4 | IPv6}
general_select_local_gateway {WAN1 | WAN2 | WAN3 | WAN4}
general_remote_end_point_type {FQDN {general_remote_end_point
fqdn <domain name> | IP-Address {general_remote_end_point
ip_address <ipaddress> | {general_remote_end_point
ipv6_address <ipv6-address>}}
general_enable_netbios {N | Y}
general_enable_rollover {N | Y {general_rollover_gateway {WAN1 |
WAN2 | WAN3 | WAN4}}
general_enable_auto_initiate_policy {N | Y}
general_enable_keep_alive {N | Y {general_ping_ipaddress
<ipaddress> | {general_ping_ipaddress6 <ipv6-address>}
{general_keep_alive_detection_period <seconds>}
{general_keep_alive_failureCount <number>}}
g
eneral_local_network_type {ANY | SINGLE
{general_local_start_address <ipaddress> |
general_local_start_address_ipv6 <ipv6-address>} | RANGE
{{general_local_start_address <ipaddress>}
{general_local_end_address <ipaddress>} |
{general_local_start_address_ipv6 <ipv6-address>}
{general_local_end_address_ipv6 <ipv6-address>}} | SUBNET
{{general_local_start_address <ipaddress>}
{general_local_subnet_mask <subnet mask>} |
{general_local_start_address_ipv6 <ipv6-address>}
{general_local_ipv6_prefix_length <prefix length>}}}
general_remote_network_type {ANY | SINGLE
{general_remote_start_address <ipaddress> |
general_remote_start_address_ipv6 <ipv6-address>} | RANGE
{{general_remote_start_address <ipaddress>}
{general_remote_end_address <ipaddress>} |
{general_remote_start_address_ipv6 <ipv6-address>}
{general_remote_end_address_ipv6 <ipv6-address>}} | SUBNET
{{general_remote_start_address <ipaddress>}
{general_remote_subnet_mask <su
bnet mask>} |
{general_remote_start_address_ipv6 <ipv6-address>}
{general_remote_ipv6_prefix_length <prefix length>}}}
manual_spi_in <number>
manual_encryption_algorithm {None | DES | 3DES | AES-128 |
AES-192 | AES-256}
manual_encryption_key_in <key>
manual_encryption_key_out <key>