📄 setup.8
字号:
.TH IPSEC_SETUP 8 "23 July 2001".\" RCSID $Id: setup.8,v 1.35 2005/01/11 17:52:50 ken Exp $.SH NAMEipsec setup \- control IPsec subsystem.SH SYNOPSIS.B ipsec.B setup[.B \-\-show|.B \-\-showonly]command.SH DESCRIPTION.I Setupcontrols the FreeS/WAN IPsec subsystem,including both the Klips kernel code and the Pluto key-negotiation daemon.(It is a synonym for the ``rc'' script for the subsystem;the system runs the equivalent of.B "ipsec setup start"at boot time,and.B "ipsec setup stop"at shutdown time, more or less.).PPThe action taken depends on the specific.IR command ,and on the contents of the.B config.B setupsection of theIPsec configuration file (\c.IR /etc/ipsec.conf ,see.IR ipsec.conf (5)).Current.IR command sare:.TP 10.B startstart Klips and Pluto,including setting up Klips to do crypto operations on the interface(s) specified in the configuration file,and (if the configuration file so specifies)setting up manually-keyed connections and/orasking Pluto to negotiate automatically-keyed connectionsto other security gateways.TP.B stopshut down Klips and Pluto,including tearing down all existing crypto connections.TP.B restartequivalent to.B stopfollowed by.B start.TP.B statusreport the status of the subsystem;normally just reports.B "IPsec running"and.BR "pluto pid \fInnn\fP" ,or.BR "IPsec stopped" ,and exits with status 0,but will go into more detail (and exit with status 1)if something strange is found.(An ``illicit'' Pluto is one that does not match the process ID inPluto's lock file;an ``orphaned'' Pluto is one with no lock file.).PPThe.B stopoperation tries to clean up properly even if assorted accidentshave occurred,e.g. Pluto having died without removing its lock file.If.B stopdiscovers that the subsystem is (supposedly) not running,it will complain,but will do its cleanup anyway before exiting with status 1..PPAlthough a number of configuration-file parameters influence.IR setup 'soperations, the key one is the.B interfacesparameter, which must be right or chaos will ensue..PPThe.B \-\-showand.B \-\-showonlyoptions cause.I setupto display the shell commands that it would execute..B \-\-showonlysuppresses their execution.Only.BR start ,.BR stop ,and.B restartcommands recognize these flags..SH FILES.ta \w'/proc/sys/net/ipv4/ip_forward'u+2n/etc/rc.d/init.d/ipsec the script itself.br/etc/init.d/ipsec alternate location for the script.br/etc/ipsec.conf IPsec configuration file.br/proc/sys/net/ipv4/ip_forward forwarding control.br/var/run/pluto/ipsec.info saved information.br/var/run/pluto/pluto.pid Pluto lock file.br/var/run/pluto/ipsec_setup.pid IPsec lock file.SH SEE ALSOipsec.conf(5), ipsec(8), ipsec_manual(8), ipsec_auto(8), route(8).SH DIAGNOSTICSAll output from the commands.B startand.B stopgoes both to standardoutput and to.IR syslogd (8),via.IR logger (1).Selected additional information is logged only to.IR syslogd (8)..SH HISTORYWritten for the FreeS/WAN project<http://www.freeswan.org>by Henry Spencer..SH BUGSOld versions of.IR logger (1)inject spurious extra newlines onto standard output.
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -