For L2TP/IPSec connections, you can enter a fixed IP address or the wildcard
address, 0.0.0.0. If you use the wildcard address, the profile accepts any
remote client connection, which is a typical scenario for secure remote
access.
For GRE/IPSec and DVMRP/IPSec connections, you must enter a fixed
address; the 0.0.0.0 wildcard address is not accepted and will return an
error.
■
Example
host1(config)#
ipsec transport profile secureL2tp virtual-router default ip address
5.5.5.5
host1(config-ipsec-transport-profile)#
■
Use the
no
version to delete the profile.
■
See ipsec transport profile.
lifetime
■
Use to set a lifetime range for the IPSec connection in volume of traffic or in
seconds or both.
■
If the PC client offers a lifetime within this range, the router accepts the offer. If
the PC client offers a lifetime outside this range, the router rejects the connection.
■
Example
host1(config-ipsec-transport-profile)#
lifetime seconds 900 86400 kilobytes
100000 4294967295
■
Use the
no
version to restore the default values, 100000–4294967295 KB and
900–86400 seconds (0.25–24 hours).
■
See lifetime.
local ip address
■
Use to specify the local endpoint (for L2TP, the LNS address) of the IPSec transport
connection and to enter Local IPSec Transport Profile Configuration mode.
■
You can enter this command multiple times in an IPSec transport profile.
■
You can enter a fixed IP address or the wildcard address, 0.0.0.0. The wildcard
address has a lower precedence than a fixed IP address.
CAUTION:
We recommend that you do not use address 0.0.0.0, because it allows
any address to accept IKE calls, and it creates a group preshared key, which is not
fully secure.
■
Example
host1(config-ipsec-transport-profile)#
local ip address 192.168.1.2
host1(config-ipsec-transport-profile-local)#
304
■
Configuring IPSec Transport Profiles
JUNOSe 11.1.x IP Services Configuration Guide
Summary of Contents for IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Page 6: ...vi...
Page 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Page 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Page 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Page 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Page 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Page 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Page 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Page 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Page 357: ...Part 2 Index Index on page 333 Index 331...
Page 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...