TMS zl Management and Configuration Guide ST.1.1.100430
A-152
Command-Line Reference
IPsec Policy Context
Replace <IP address/mask> with the IP address (including the subnet
mask) that the TMS zl Module will use to route traffic from the remote clients.
Type an address in a subnet that you can reserve for the remote clients; this
subnet cannot be configured on a TMS VLAN.
If you select the host option, replace <IP address> with the IP address that
the TMS zl Module will use to route traffic from the remote clients. The IP
address must not be in use on a TMS VLAN.
firewall. This command sets the firewall zone for remote clients after they
receive their IKE mode config IP settings. Traffic received from the IKE mode
config addresses will use this zone as the source zone; traffic destined to these
addresses will use this address as the destination zone. To set the IRAS firewall
zone, enter the following command:
Syntax: firewall zone <zone>
Replace <zone> with one of the following:
■ self
■ internal
■ external
■ dmz
■ zone1
■ zone2
■ zone3
■ zone4
■ zone5
■ zone6
■ <user-named zone>
ip-range. This command sets the IP address pool for remote clients. Each
remote client will be assigned an address from this pool while visiting your
private network. You can configure several address ranges. To configure (or
delete) an address range, enter the following:
Syntax: [no] ip-range <start IP address> <end IP address>
Replace <start IP address> and <end IP address> with the first IP address
and the last IP address for the address range, respectively.
dns. To configure the remote clients’ DNS servers while they are on the VPN
connection, enter the following command: