host1(config-ipsec-transport-profile)#
transform-set esp-3des-hmac-sha
esp-3des-hmac-md5
To display the available transform sets, issue the
transform-set ?
command.
■
Specify the local endpoint (for L2TP, the LNS address) of the IPSec transport
connection, and enter Local IPSec Transport Profile mode.
host1(config-ipsec-transport-profile)#
local ip address 10.10.1.1
host1(config-ipsec-transport-profile-local)#
■
(Optional) Configure a key for IKE negotiations. For example:
Enter the unencrypted key. The router encrypts the key and stores it in encrypted
form. You can no longer retrieve the unencrypted key.
host1(config-ipsec-transport-profile-local)#
pre-share secretforGre
application
Use to specify the types of application secured by connections created with this
IPSec transport profile. You can specify multiple applications on the same
command line:
■
■
dvmrp
—Secures DVMRP tunnel traffic
■
gre
—Secures GRE tunnel traffic
■
l2tp
—Secures L2TP traffic
■
l2tp-nat-passthrough—
Secures L2TP traffic and also allows clients to connect
from behind NAT devices that support IPSec passthrough. To allow these
clients to connect, the router:
■
Does not generate or verify UDP checksums. This does not compromise
security, because IPSec protects UDP packets with an authentication
algorithm far stronger than UDP checksums.
■
Provides IPSec filtering based on the received IP address (the NAT public
IP address), rather than filtering based on the negotiated IKE identities.
■
Example
host1(config-ipsec-transport-profile)#
application gre dvmrp l2tp
■
Use the
no
version to return to the default application type, L2TP.
■
See application.
ipsec transport profile
Use to create an IPSec transport profile and to enter IPSec Transport Profile
Configuration mode. To create a new profile, you must include the following
keywords:
■
■
virtual-router—
Name of the virtual router on which you want to create the
profile
■
ip address
—Remote endpoint for the IPSec transport connection.
Configuring IPSec Transport Profiles
■
303
Chapter 12: Securing L2TP and IP Tunnels with IPSec
Summary of Contents for IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Page 6: ...vi...
Page 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Page 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Page 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Page 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Page 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Page 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Page 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Page 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Page 357: ...Part 2 Index Index on page 333 Index 331...
Page 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...