Fortinet fortigate-200a Betriebsanweisung

Seite von 392
VPN 
CLI configuration
FortiGate-300A Administration Guide
01-28006-0092-20041105
 279
config vpn ipsec vip
edit <vip_integer>
unset <keyword>
end
config vpn ipsec vip
delete <vip_integer>
end
get vpn ipsec vip [<vip_integer>]
show vpn ipsec vip [<vip_integer>]
Example
The following commands add IPSec VIP entries for two remote hosts that can be 
accessed by a FortiGate unit through an IPSec VPN tunnel on the external 
interface of the FortiGate unit. Similar commands must be entered on the FortiGate 
unit at the other end of the IPSec VPN tunnel.
config vpn ipsec vip
edit 1
set ip 192.168.12.1
set out-interface external
next
edit 2
set ip 192.168.12.2
set out-interface external
end
This example shows how to display the settings for the vpn ipsec vip command.
get vpn ipsec vip
This example shows how to display the settings for the VIP entry named 1.
get vpn ipsec vip 1
This example shows how to display the current configuration of all existing VIP 
entries.
show vpn ipsec vip
ipsec vip command keywords and variables
Keywords and variables
Description
Default
Availability
ip <address_ipv4>
The IP address of the destination 
host on the destination network.
0.0.0.0 All models.
out-interface
<interface-name_str>
The name of the FortiGate interface 
to the destination network.
null
All models.
Note: Typing next lets you define another VIP address without leaving the vip shell.