User`s guide

203
Related CLI Commands
Entity
Instance
Parameter
Equivalent Web Parameter
ike 0 deblevel
0 = Off
1 = Low
2 = Medium
3 = High
4 = Very High
Debug Level
ike 0 ipaddfilt
Comma separated
list of IP addresses
Debug IP Address Filter
ike 0 debug on, off Forward debug to port
ConfigurationNetwork > Virtual Private Networking (VPN) > IPsec > IKE
> IKE n
Use the following settings for negotiation
Defines the settings used during the IKE negotiation
Encryption
Defines the encryption algorithm used. The options are
None
DES
3DES
AES (128 bit keys)
AES (192 bit keys)
AES (256 bit keys)
Authentication
Defines the authentication algorithm used. The options are
None
MD5
SHA1
Mode
Defines the negotiation mode. The options are
Main
Aggressive
Historically, fixed IP addresses have been used in setting up IPSec tunnels. Today it is
more common, particularly with Internet ISPs, to dynamically allocate the user a
temporary IP address as part of the process of connecting to the Internet. In this case,
the source IP address of the party trying to initiate the tunnel is variable and cannot be
pre-configured.
In Main mode (i.e. non-aggressive), the source IP address must be known i.e. this mode
can only be used over the Internet if the ISP provides a fixed IP address to the user or
you are using X.509 certificates.