Use the RemoteIdentity statement to encapsulate remote IKE identity information. This statement defines a singule or wildcard value remote identity for use in negotiation of dynamic VPN tunnels.
Restriction: This statement is valid only for V1R12 and later releases. See General syntax rules for Policy Agent for details.
>>-RemoteIdentity--+------+--| Put Braces and Parameters on Separate Lines |->< '-name-' Put Braces and Parameters on Separate Lines |--+-{-----------------------------+----------------------------| +-| RemoteIdentity Parameters |-+ '-}-----------------------------' RemoteIdentity Parameters |--Identity--+-IpAddr authid------------+-----------------------| +-KeyID -+-Ascii authid--+-+ | +-Ebcdic authid-+ | | '-Hex authid----' | +-Fqdn authid--------------+ +-UserAtFqdn authid--------+ '-X500dn authid------------'
Rule: If this RemoteIdentity statement is not specified as an inline statement, you must specify a name value.
If you do not specify a name for an inline RemoteIdentity statement, a nonpersistent system name results.1.2.3.0/24 or 1::9/124
1.2.3.4-1.2.3.100 or 1::0-1::F
Restriction: This value is valid only for V1R12 and later releases. See General syntax rules for Policy Agent for details.
The ASCII or EBCDIC KeyID value can be defined as a quoted string or a single value.
Restriction: When the value contains embedded blanks, you must specify the entire parameter value within the first 1 536 characters of the configuration file line.
Identity KeyID Ascii ASC # comment" value used: ASC
Identity KeyID EBCDIC EBC comment value used: EBC
Identity KeyID ASCII "ASC 98Z" value used: ASC 98Z
Identity KeyID EBCDIC EBC 98Z" value used: EBC
Identity KeyID ASCII "AsC 98Z value used: "AsC
Identity KeyID EBCDIC "Ebc " " Ebc" value used: Ebc " " Ebc
Identity KeyID ASCII "Asc Asc" " value used: Asc Asc"
The Fqdn value can be coded with a wildcard value in the leftmost portion preceding the first period. For example, *.ibm.com is allowed.
The leftmost portion cannot be a partial wildcard value. For example, *net.ibm.com is not allowed.
For example, ibm@vnet.ibm.com is allowed. The maximum length accepted is 1024 characters. The UserAtFqdn value cannot begin or end with a dot (.) and cannot contain consecutive dots.
The user portion can be a wildcard value (for example, *@vnet.ibm.com). Alternatively, the leftmost portion of the Fqdn value can be a wildcard value. For example, *.ibm.com is allowed.
The leftmost portion of the DN can be a wildcard value. For example, *,OU=endicott,O=ibm,C=US is allowed.
Non-initial RDNs cannot be a wildcard value. For example, CN="John Doe",*,O=ibm,C=US is not allowed.
Identity X500DN cn=#my identity
value used: cn=#my identity
Restriction: When the value contains embedded blanks, you must specify the entire parameter value within the first 1 536 characters of the configuration file line.