Table of contents
SCALANCE S615 Command Line Interface
Configuration Manual, 06/2015, C79000-G8976-C406-02
17
9.3.4.2 addr-mode ............................................................................................................................. 368
9.3.4.3 conn-mode ............................................................................................................................ 369
9.3.4.4 subnet ................................................................................................................................... 369
9.3.4.5 vir-ip ...................................................................................................................................... 370
9.3.4.6 no vir-ip ................................................................................................................................. 371
9.3.5 Commands in the IPSEC CONNECTION configuration mode ............................................. 372
9.3.5.1 authentication ........................................................................................................................ 372
9.3.5.2 k-proto ................................................................................................................................... 372
9.3.5.3 loc-subnet ............................................................................................................................. 373
9.3.5.4 rmend name .......................................................................................................................... 374
9.3.5.5 operation ............................................................................................................................... 375
9.3.5.6 phase .................................................................................................................................... 376
9.3.5.7 timeout .................................................................................................................................. 376
9.3.5.8 vir-ip ...................................................................................................................................... 377
9.3.5.9 no vir-ip ................................................................................................................................. 378
9.3.6 Commands in the IPSEC AUTHENTICATION configuration mode ..................................... 379
9.3.6.1 auth cacert ............................................................................................................................ 379
9.3.6.2 auth psk ................................................................................................................................ 380
9.3.6.3 auth remcert .......................................................................................................................... 381
9.3.6.4 no auth .................................................................................................................................. 381
9.3.6.5 local-id ................................................................................................................................... 382
9.3.6.6 no local-id .............................................................................................................................. 383
9.3.6.7 rem-id .................................................................................................................................... 384
9.3.6.8 no rem-id ............................................................................................................................... 384
9.3.7 Commands in the IPSEC PHASE1 configuration mode ....................................................... 385
9.3.7.1 aggressive ............................................................................................................................. 385
9.3.7.2 no aggressive ........................................................................................................................ 386
9.3.7.3 default-ciphers ...................................................................................................................... 387
9.3.7.4 no default-ciphers ................................................................................................................. 388
9.3.7.5 dpd ........................................................................................................................................ 388
9.3.7.6 no dpd ................................................................................................................................... 389
9.3.7.7 dpd-period
............................................................................................................................. 390
9.3.7.8 dpd-timeout ........................................................................................................................... 391
9.3.7.9 ike-auth ................................................................................................................................. 391
9.3.7.10 ike-encryption ........................................................................................................................ 392
9.3.7.11 ike-keyderivation ................................................................................................................... 394
9.3.7.12 ike-keytries ............................................................................................................................ 395
9.3.7.13 ike-lifetime ............................................................................................................................. 395
9.3.8 Commands in the IPSEC PHASE2 configuration mode ....................................................... 396
9.3.8.1 auto-fwrules .......................................................................................................................... 396
9.3.8.2 no auto-fwrules ..................................................................................................................... 397
9.3.8.3 default-ciphers ...................................................................................................................... 398
9.3.8.4 no default-ciphers ................................................................................................................. 399
9.3.8.5 esp-auth ................................................................................................................................ 400
9.3.8.6 esp-encryption ...................................................................................................................... 400
9.3.8.7 esp-keyderivation .................................................................................................................. 402
9.3.8.8 lifetime ................................................................................................................................... 403
9.3.8.9 lifebyte ................................................................................................................................... 404
9.3.8.10 proto ...................................................................................................................................... 405
9.3.8.11 port ........................................................................................................................................ 406
9.4 Certificates ............................................................................................................................ 407
9.4.1 Commands in the global configuration mode ....................................................................... 407