1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
|
C set [Phase 1]:2.2.2.2=peer-2.2.2.2 force
C set [peer-2.2.2.2]:Phase=1 force
C set [peer-2.2.2.2]:Address=2.2.2.2 force
C set [peer-2.2.2.2]:Configuration=phase1-peer-2.2.2.2 force
C set [phase1-peer-2.2.2.2]:EXCHANGE_TYPE=ID_PROT force
C add [phase1-peer-2.2.2.2]:Transforms=phase1-transform-peer-2.2.2.2-RSA_SIG-SHA-AES128,128:256-MODP_1024 force
C set [phase1-transform-peer-2.2.2.2-RSA_SIG-SHA-AES128,128:256-MODP_1024]:AUTHENTICATION_METHOD=RSA_SIG force
C set [phase1-transform-peer-2.2.2.2-RSA_SIG-SHA-AES128,128:256-MODP_1024]:HASH_ALGORITHM=SHA force
C set [phase1-transform-peer-2.2.2.2-RSA_SIG-SHA-AES128,128:256-MODP_1024]:ENCRYPTION_ALGORITHM=AES_CBC force
C set [phase1-transform-peer-2.2.2.2-RSA_SIG-SHA-AES128,128:256-MODP_1024]:KEY_LENGTH=128,128:256 force
C set [phase1-transform-peer-2.2.2.2-RSA_SIG-SHA-AES128,128:256-MODP_1024]:GROUP_DESCRIPTION=MODP_1024 force
C set [phase1-transform-peer-2.2.2.2-RSA_SIG-SHA-AES128,128:256-MODP_1024]:Life=LIFE_MAIN_MODE force
C set [from-1.1.1.1-to-2.2.2.2]:Phase=2 force
C set [from-1.1.1.1-to-2.2.2.2]:ISAKMP-peer=peer-2.2.2.2 force
C set [from-1.1.1.1-to-2.2.2.2]:Configuration=phase2-from-1.1.1.1-to-2.2.2.2 force
C set [from-1.1.1.1-to-2.2.2.2]:Local-ID=from-1.1.1.1 force
C set [from-1.1.1.1-to-2.2.2.2]:Remote-ID=to-2.2.2.2 force
C set [phase2-from-1.1.1.1-to-2.2.2.2]:EXCHANGE_TYPE=QUICK_MODE force
C set [phase2-from-1.1.1.1-to-2.2.2.2]:Suites=phase2-suite-from-1.1.1.1-to-2.2.2.2 force
C set [phase2-suite-from-1.1.1.1-to-2.2.2.2]:Protocols=phase2-protocol-from-1.1.1.1-to-2.2.2.2 force
C set [phase2-protocol-from-1.1.1.1-to-2.2.2.2]:PROTOCOL_ID=IPSEC_ESP force
C set [phase2-protocol-from-1.1.1.1-to-2.2.2.2]:Transforms=phase2-transform-from-1.1.1.1-to-2.2.2.2-AES128,128:256-SHA2_256-MODP_1024-TUNNEL force
C set [phase2-transform-from-1.1.1.1-to-2.2.2.2-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:TRANSFORM_ID=AES force
C set [phase2-transform-from-1.1.1.1-to-2.2.2.2-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:KEY_LENGTH=128,128:256 force
C set [phase2-transform-from-1.1.1.1-to-2.2.2.2-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force
C set [phase2-transform-from-1.1.1.1-to-2.2.2.2-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force
C set [phase2-transform-from-1.1.1.1-to-2.2.2.2-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:GROUP_DESCRIPTION=MODP_1024 force
C set [phase2-transform-from-1.1.1.1-to-2.2.2.2-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:Life=LIFE_QUICK_MODE force
C set [from-1.1.1.1]:ID-type=IPV4_ADDR force
C set [from-1.1.1.1]:Address=1.1.1.1 force
C set [to-2.2.2.2]:ID-type=IPV4_ADDR force
C set [to-2.2.2.2]:Address=2.2.2.2 force
C add [Phase 2]:Connections=from-1.1.1.1-to-2.2.2.2
C set [Phase 1]:Default=peer-default force
C set [peer-default]:Phase=1 force
C set [peer-default]:Configuration=phase1-peer-default force
C set [phase1-peer-default]:EXCHANGE_TYPE=ID_PROT force
C add [phase1-peer-default]:Transforms=phase1-transform-peer-default-RSA_SIG-SHA-AES128,128:256-MODP_1024 force
C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128,128:256-MODP_1024]:AUTHENTICATION_METHOD=RSA_SIG force
C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128,128:256-MODP_1024]:HASH_ALGORITHM=SHA force
C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128,128:256-MODP_1024]:ENCRYPTION_ALGORITHM=AES_CBC force
C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128,128:256-MODP_1024]:KEY_LENGTH=128,128:256 force
C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128,128:256-MODP_1024]:GROUP_DESCRIPTION=MODP_1024 force
C set [phase1-transform-peer-default-RSA_SIG-SHA-AES128,128:256-MODP_1024]:Life=LIFE_MAIN_MODE force
C set [from-3.3.3.3-to-4.4.4.4]:Phase=2 force
C set [from-3.3.3.3-to-4.4.4.4]:ISAKMP-peer=peer-default force
C set [from-3.3.3.3-to-4.4.4.4]:Configuration=phase2-from-3.3.3.3-to-4.4.4.4 force
C set [from-3.3.3.3-to-4.4.4.4]:Local-ID=from-3.3.3.3 force
C set [from-3.3.3.3-to-4.4.4.4]:Remote-ID=to-4.4.4.4 force
C set [phase2-from-3.3.3.3-to-4.4.4.4]:EXCHANGE_TYPE=QUICK_MODE force
C set [phase2-from-3.3.3.3-to-4.4.4.4]:Suites=phase2-suite-from-3.3.3.3-to-4.4.4.4 force
C set [phase2-suite-from-3.3.3.3-to-4.4.4.4]:Protocols=phase2-protocol-from-3.3.3.3-to-4.4.4.4 force
C set [phase2-protocol-from-3.3.3.3-to-4.4.4.4]:PROTOCOL_ID=IPSEC_ESP force
C set [phase2-protocol-from-3.3.3.3-to-4.4.4.4]:Transforms=phase2-transform-from-3.3.3.3-to-4.4.4.4-AES128,128:256-SHA2_256-MODP_1024-TUNNEL force
C set [phase2-transform-from-3.3.3.3-to-4.4.4.4-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:TRANSFORM_ID=AES force
C set [phase2-transform-from-3.3.3.3-to-4.4.4.4-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:KEY_LENGTH=128,128:256 force
C set [phase2-transform-from-3.3.3.3-to-4.4.4.4-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force
C set [phase2-transform-from-3.3.3.3-to-4.4.4.4-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force
C set [phase2-transform-from-3.3.3.3-to-4.4.4.4-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:GROUP_DESCRIPTION=MODP_1024 force
C set [phase2-transform-from-3.3.3.3-to-4.4.4.4-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:Life=LIFE_QUICK_MODE force
C set [from-3.3.3.3]:ID-type=IPV4_ADDR force
C set [from-3.3.3.3]:Address=3.3.3.3 force
C set [to-4.4.4.4]:ID-type=IPV4_ADDR force
C set [to-4.4.4.4]:Address=4.4.4.4 force
C add [Phase 2]:Connections=from-3.3.3.3-to-4.4.4.4
C set [Phase 1]:9.9.9.9=peer-9.9.9.9 force
C set [peer-9.9.9.9]:Phase=1 force
C set [peer-9.9.9.9]:Address=9.9.9.9 force
C set [peer-9.9.9.9]:Configuration=phase1-peer-9.9.9.9 force
C set [phase1-peer-9.9.9.9]:EXCHANGE_TYPE=ID_PROT force
C add [phase1-peer-9.9.9.9]:Transforms=phase1-transform-peer-9.9.9.9-RSA_SIG-SHA-AES128,128:256-MODP_1024 force
C set [phase1-transform-peer-9.9.9.9-RSA_SIG-SHA-AES128,128:256-MODP_1024]:AUTHENTICATION_METHOD=RSA_SIG force
C set [phase1-transform-peer-9.9.9.9-RSA_SIG-SHA-AES128,128:256-MODP_1024]:HASH_ALGORITHM=SHA force
C set [phase1-transform-peer-9.9.9.9-RSA_SIG-SHA-AES128,128:256-MODP_1024]:ENCRYPTION_ALGORITHM=AES_CBC force
C set [phase1-transform-peer-9.9.9.9-RSA_SIG-SHA-AES128,128:256-MODP_1024]:KEY_LENGTH=128,128:256 force
C set [phase1-transform-peer-9.9.9.9-RSA_SIG-SHA-AES128,128:256-MODP_1024]:GROUP_DESCRIPTION=MODP_1024 force
C set [phase1-transform-peer-9.9.9.9-RSA_SIG-SHA-AES128,128:256-MODP_1024]:Life=LIFE_MAIN_MODE force
C set [from-5.5.5.5-to-6.6.6.6]:Phase=2 force
C set [from-5.5.5.5-to-6.6.6.6]:ISAKMP-peer=peer-9.9.9.9 force
C set [from-5.5.5.5-to-6.6.6.6]:Configuration=phase2-from-5.5.5.5-to-6.6.6.6 force
C set [from-5.5.5.5-to-6.6.6.6]:Local-ID=from-5.5.5.5 force
C set [from-5.5.5.5-to-6.6.6.6]:Remote-ID=to-6.6.6.6 force
C set [phase2-from-5.5.5.5-to-6.6.6.6]:EXCHANGE_TYPE=QUICK_MODE force
C set [phase2-from-5.5.5.5-to-6.6.6.6]:Suites=phase2-suite-from-5.5.5.5-to-6.6.6.6 force
C set [phase2-suite-from-5.5.5.5-to-6.6.6.6]:Protocols=phase2-protocol-from-5.5.5.5-to-6.6.6.6 force
C set [phase2-protocol-from-5.5.5.5-to-6.6.6.6]:PROTOCOL_ID=IPSEC_ESP force
C set [phase2-protocol-from-5.5.5.5-to-6.6.6.6]:Transforms=phase2-transform-from-5.5.5.5-to-6.6.6.6-AES128,128:256-SHA2_256-MODP_1024-TUNNEL force
C set [phase2-transform-from-5.5.5.5-to-6.6.6.6-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:TRANSFORM_ID=AES force
C set [phase2-transform-from-5.5.5.5-to-6.6.6.6-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:KEY_LENGTH=128,128:256 force
C set [phase2-transform-from-5.5.5.5-to-6.6.6.6-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:ENCAPSULATION_MODE=TUNNEL force
C set [phase2-transform-from-5.5.5.5-to-6.6.6.6-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:AUTHENTICATION_ALGORITHM=HMAC_SHA2_256 force
C set [phase2-transform-from-5.5.5.5-to-6.6.6.6-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:GROUP_DESCRIPTION=MODP_1024 force
C set [phase2-transform-from-5.5.5.5-to-6.6.6.6-AES128,128:256-SHA2_256-MODP_1024-TUNNEL]:Life=LIFE_QUICK_MODE force
C set [from-5.5.5.5]:ID-type=IPV4_ADDR force
C set [from-5.5.5.5]:Address=5.5.5.5 force
C set [to-6.6.6.6]:ID-type=IPV4_ADDR force
C set [to-6.6.6.6]:Address=6.6.6.6 force
C add [Phase 2]:Connections=from-5.5.5.5-to-6.6.6.6
|