Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Head Office:
- GATE01(Primary) (NetLab1) # sho vpn ipsec phase1-interface
- config vpn ipsec phase1-interface
- edit "S2S_1"
- set interface "NL1-1"
- set local-gw 172.16.1.1
- set peertype any
- set net-device disable
- set proposal aes256-sha512 aes256-sha256
- set comments "VPN: S2S_1 -- Created by VPN wizard"
- set dhgrp 21 20
- set wizard-type static-fortigate
- set auto-discovery-sender enable
- set remote-gw 172.16.1.2
- set psksecret ENC icHbdHoDV+Raoke5BGQwL6lO+CaiqD5TukT8ffxhHXyWpF5xe5pM/jwdYazC8b7jPiU2j7FGJBulsiMyjfMmOf0PgBXX+03aoCQuSyuiYONCPFm072tycpDWduP37MfCSHLIWTQczNHOBnpyTd3JifXGHUgnzO+dZ7rmR986Xyondv1Um64QsODvc0N6mlLL4tM+GVlmMjY3dkVA
- next
- end
- GATE01(Primary) (NetLab1) # sho vpn ipsec phase2-interface
- config vpn ipsec phase2-interface
- edit "S2S_1"
- set phase1name "S2S_1"
- set proposal aes256-sha512 aes256-sha256
- set dhgrp 21 20
- set auto-negotiate enable
- set comments "VPN: S2S_1 -- Created by VPN wizard"
- next
- end
- GATE01(Primary) (NetLab1) # sho sys interface S2S_1
- config system interface
- edit "S2S_1"
- set vdom "NetLab1"
- set ip 10.17.255.2 255.255.255.255
- set allowaccess ping
- set type tunnel
- set remote-ip 10.17.255.1 255.255.255.0
- set snmp-index 72
- set interface "NL1-1"
- next
- end
- GATE01(Primary) (NetLab1) # sho sys interface NL1-2
- config system interface
- edit "NL1-2"
- set vdom "NetLab1"
- set ip 172.16.1.1 255.255.255.252
- set allowaccess ping https
- set alias "NetLab FW1-1"
- set device-identification enable
- set role lan
- set snmp-index 94
- set ip-managed-by-fortiipam disable
- set interface "fortilink"
- set vlanid 1902
- next
- end
- GATE01(Primary) (NetLab1) # diag vpn ipsec status
- All ipsec crypto devices in use:
- np7_0:
- Encryption (encrypted/decrypted)
- null : 0 0
- des : 0 0
- 3des : 0 0
- aes : 4558 8192
- aes-gcm : 0 0
- aria : 0 0
- seed : 0 0
- chacha20poly1305 : 0 0
- Integrity (generated/validated)
- null : 0 0
- md5 : 0 0
- sha1 : 4558 2048
- sha256 : 0 0
- sha384 : 0 0
- sha512 : 0 6144
- NPU Host Offloading:
- Encryption (encrypted/decrypted)
- null : 0 0
- des : 0 0
- 3des : 0 0
- aes : 14205 0
- aes-gcm : 0 0
- aria : 0 0
- seed : 0 0
- chacha20poly1305 : 0 0
- Integrity (generated/validated)
- null : 0 0
- md5 : 0 0
- sha1 : 14212 0
- sha256 : 0 0
- sha384 : 0 0
- sha512 : 0 0
- CP9:
- Encryption (encrypted/decrypted)
- null : 0 0
- des : 0 0
- 3des : 0 0
- aes : 92 6661
- aes-gcm : 0 0
- aria : 0 0
- seed : 0 0
- chacha20poly1305 : 0 0
- Integrity (generated/validated)
- null : 0 0
- md5 : 0 0
- sha1 : 92 6653
- sha256 : 0 0
- sha384 : 0 0
- sha512 : 0 8
- INTEL:
- Encryption (encrypted/decrypted)
- null : 0 0
- des : 0 0
- 3des : 0 0
- aes : 0 0
- aes-gcm : 0 0
- aria : 0 0
- seed : 0 0
- chacha20poly1305 : 0 0
- Integrity (generated/validated)
- null : 0 0
- md5 : 0 0
- sha1 : 0 0
- sha256 : 0 0
- sha384 : 0 0
- sha512 : 0 0
- SOFTWARE:
- Encryption (encrypted/decrypted)
- null : 0 0
- des : 0 0
- 3des : 0 0
- aes : 0 0
- aes-gcm : 0 0
- aria : 0 0
- seed : 0 0
- chacha20poly1305 : 0 0
- Integrity (generated/validated)
- null : 0 0
- md5 : 0 0
- sha1 : 0 0
- sha256 : 0 0
- sha384 : 0 0
- sha512 : 0 0
- GATE01(Primary) (NetLab1) # diag vpn tunnel list
- list all ipsec tunnel in vd 1
- ------------------------------------------------------
- name=S2S_1 ver=1 serial=309 172.16.1.1:0->172.16.1.2:0 nexthop= tun_id=172.16.1.2 tun_id6=::172.16.1.2 status=up dst_mtu=1500 weight=1
- bound_if=103 real_if=104 lgwy=static/1 tun=intf mode=auto/1 encap=none/552 options[0228]=npu frag-rfc run_state=0 role=sync-primary accept_traffic=1 overlay_id=0
- proxyid_num=1 child_num=0 refcnt=4 ilast=25 olast=25 ad=s/1
- stat: rxp=1 txp=68 rxb=84 txb=5208
- dpd: mode=on-demand on=1 status=ok idle=20000ms retry=3 count=0 seqno=25
- natt: mode=none draft=0 interval=0 remote_port=0
- fec: egress=0 ingress=0
- proxyid=S2S_1 proto=0 sa=1 ref=3 serial=5 auto-negotiate ads
- src: 0:0.0.0.0-255.255.255.255:0
- dst: 0:0.0.0.0-255.255.255.255:0
- SA: ref=4 options=18a27 type=00 soft=0 mtu=1280 expire=41457/0B replaywin=2048
- seqno=1 esn=0 replaywin_lastseq=00000002 qat=0 rekey=0 hash_search_len=1
- life: type=01 bytes=0/0 timeout=42899/43200
- dec: spi=d0bfcd16 esp=aes key=32 c312952c1aec7fb7ffc87c21c6224808dca19bd7228438ad527b9910a65959a2
- ah=sha512 key=64 7fb0c38a3a7ec42721bd0c7f09381dcd8360042cb44759dccd17b8eddfe477c38c96b36c58c1ee468b05a3011483ca61ff2d01755369bed242d6738e15070184
- enc: spi=33cdc016 esp=aes key=32 6fdd4a7f76b1db106911dba86908a4054d44cc66dfb574c4a2a0cea292d51750
- ah=sha512 key=64 5b1255a37758284828a8dd75eea02a0e4ba45f3ba0b1c4abf4829e641204b53daf98f9e81b573e862f4777e7d4f099e999251d2e556ffb53dd65ddc5be680082
- dec:pkts/bytes=1/84, enc:pkts/bytes=68/5208
- npu_flag=02 npu_rgwy=172.16.1.2:0 npu_lgwy=172.16.1.1:0 npu_selid=316
- dec_npuid=1 enc_npuid=0 dec_engid=-1 enc_engid=-1 dec_saidx=664 enc_saidx=-1
- GATE01(Primary) (NetLab1) # diag vpn tun stat
- dev=2 attached=0 tunnel=2 proxyid=1 sa=1 conc=0 up=1 crypto_work=0 crypto_work_dropped=0
- mr_grps=0 mr_children=0 mr_flood_list=0 mr_fw_list=0
Advertisement
Add Comment
Please, Sign In to add comment