Concept Guide

Table Of Contents
crypto-local ipsec-map
crypto-local
crypto-local ipsec-map <map> <priority>
disable
dst-net <ipaddr> <mask>
factory-cert-auth
force-natt
ip access-group <access-group> in
ip-compression disable|enable
no ...
local-fqdn <local_id_fqdn>
peer-cert-dn <peer-dn>
peer-fqdn any-fqdn|{peer-fqdn <peer-id-fqdn>}
peer-ip <ipaddr>
pre-connect {disable|enable}
set ca-certificate <cacert-name>
set ike1-policy <policy-v1-number>
set ikev2-policy <policy-v2-number>
set pfs {group1|group2|group14|group19|group20}
set security-association lifetime kilobytes <kilobytes>
set security-association lifetime seconds <seconds>
set server-certificate <cert-name>
set transform-set <name1> [<name2>] [<name3>] [<name4>]
src-net <ipaddr> <mask>
trusted {disable|enable}
version v1|v2
vlan <vlan>
Description
This command configures IPsec mapping for site-to-site VPNs.
Syntax
Parameter Description Range Default
<map>
Name of the IPsec map.
<priority>
Priority of the entry. 1-9998
dst-net
IP address and netmask for the destination
network.
disable
Issue this command to disable an existing
IPsec map. New maps are enabled by
default.
force-natt
Include this parameter to always enforce
UDP 4500 for IKE and IPsec. This option is
disabled by default.
Dell Networking W-Series ArubaOS 6.5.x | Reference Guide crypto-local ipsec-map | 313