⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 auto.8

📁 This a good VPN source
💻 8
字号:
.TH IPSEC_AUTO 8 "31 Jan 2002".\" RCSID $Id: auto.8,v 1.41 2003/01/09 08:36:57 dhr Exp $.SH NAMEipsec auto \- control automatically-keyed IPsec connections.SH SYNOPSIS.B ipsec.B auto[.B \-\-show] [.B \-\-showonly] [.B \-\-asynchronous].br\ \ \ [.B \-\-configconfigfile] [.B \-\-verbose].br\ \ \ operationconnection.sp.B ipsec.B auto[.B \-\-show] [.B \-\-showonly] operation.SH DESCRIPTION.I Automanipulates automatically-keyed FreeS/WAN IPsec connections,setting them up and shutting them downbased on the information in the IPsec configuration file.In the normal usage,.I connectionis the name of a connection specification in the configuration file;.I operationis.BR \-\-add ,.BR \-\-delete ,.BR \-\-replace ,.BR \-\-up ,.BR \-\-down ,.BR \-\-route ,or.BR \-\-unroute .The.BR \-\-ready ,.BR \-\-rereadsecrets ,.BR \-\-rereadgroups ,and.BR \-\-status.I operationsdo not take a connection name..I Autogenerates suitablecommands and feeds them to a shell for execution..PPThe.B \-\-addoperation adds a connection specification to the internal databasewithin.IR pluto ;it will fail if.I plutoalready has a specification by that name.The.B \-\-deleteoperation deletes a connection specification from.IR pluto 'sinternal database (also tearing down any connections based on it);it will fail if the specification does not exist.The.B \-\-replaceoperation is equivalent to.B \-\-delete(if there is already a specification by the given name)followed by.BR \-\-add ,and is a convenience for updating.IR pluto 'sinternal specification to match an external one.(Note that a.B \-\-rereadsecretsmay also be needed.)The.B \-\-rereadgroupsoperation causes any changes to the policy group files to take effect(this is currently a synonym for.BR \-\-ready ,but that may change).None of the other operations alters the internal database..PPThe.B \-\-upoperation asks.I plutoto establish a connection based on an entry in its internal database.The.B \-\-downoperation tells.I plutoto tear down such a connection..PPNormally,.I plutoestablishes a route to the destination specified for a connection aspart of the.B \-\-upoperation.However, the route and only the route can be established with the.B \-\-routeoperation.Until and unless an actual connection is established,this discards any packets sent there,which may be preferable to having them sent elsewhere based on a moregeneral route (e.g., a default route)..PPNormally,.IR pluto 'sroute to a destination remains in place when a.B \-\-downoperation is used to take the connection down(or if connection setup, or later automatic rekeying, fails).This permits establishing a new connection (perhaps using adifferent specification; the route is altered as necessary)without having a ``window'' in which packets might go elsewherebased on a more general route.Such a route can be removed using the.B \-\-unrouteoperation(and is implicitly removed by.BR \-\-delete )..PPThe.B \-\-readyoperation tells.I plutoto listen for connection-setup requests from other hosts.Doing an.B \-\-upoperation before doing.B \-\-readyon both ends is futile and will not work,although this is now automated as part of IPsec startup andshould not normally be an issue..PPThe.B \-\-statusoperation asks.I plutofor current connection status.The output format is ad-hoc and likely to change..PPThe.B \-\-rereadsecretsoperation tells.I plutoto re-read the.I /etc/ipsec.secretssecret-keys file,which it normally reads only at startup time.(This is currently a synonym for.BR \-\-ready ,but that may change.).PPThe.B \-\-showoption turns on the.B \-xoption of the shell used to execute the commands,so each command is shown as it is executed..PPThe.B \-\-showonlyoption causes.I autoto show the commands it would run, on standard output,and not run them..PPThe.B \-\-asynchronousoption, applicable only to the.B upoperation,tells.I plutoto attempt to establish the connection,but does not delay to report results.This is especially useful to start multiple connections in parallelwhen network links are slow..PPThe.B \-\-verboseoption instructs.I autoto pass through all output from.IR ipsec_whack (8),including log output that is normally filtered out as uninteresting..PPThe.B \-\-configoption specifies a non-standard location for the IPsecconfiguration file (default.IR /etc/ipsec.conf )..PPSee.IR ipsec.conf (5)for details of the configuration file.Apart from the basic parameters which specify the endpoints and routingof a connection (\fBleft\fRand.BR right ,plus possibly.BR leftsubnet ,.BR leftnexthop ,.BR leftfirewall ,their.B rightequivalents,and perhaps.BR type ),an.I autoconnection almost certainly needs a.B keyingtriesparameter (since the.B keyingtriesdefault is poorly chosen)..SH FILES.ta \w'/var/run/ipsec.info'u+4n/etc/ipsec.conf	default IPSEC configuration file.br/var/run/ipsec.info	\fB%defaultroute\fR information.SH SEE ALSOipsec.conf(5), ipsec(8), ipsec_pluto(8), ipsec_whack(8), ipsec_manual(8).SH HISTORYWritten for the FreeS/WAN project<http://www.freeswan.org>by Henry Spencer..SH BUGSAlthough an.B \-\-upoperation does connection setup on both ends,.B \-\-downtears only one end of the connection down(although the orphaned end will eventually time out)..PPThere is no support for.B passthroughconnections..PPA connection description which uses.B %defaultroutefor one of its.B nexthopparameters but not the other may be falselyrejected as erroneous in some circumstances..PPThe exit status of.B \-\-showonlydoes not always reflect errors discovered during processing of the request.(This is fine for human inspection, but not so good for use in scripts.)

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -