erx2(config-manual-key)#
exit
erx2(config)#
ipsec key manual pre-share 5.3.0.1
erx2(config-manual-key)#
key customerASecret
erx2(config-manual-key)#
exit
erx2(config)#
ipsec key manual pre-share 5.1.0.2
erx2(config-manual-key)#
key customerBSecret
erx2(config-manual-key)#
exit
erx2(config)#
ipsec key manual pre-share 5.3.0.2
erx2(config-manual-key)#
key customerBSecret
erx2(config-manual-key)#
exit
erx3(config)#
ipsec key manual pre-share 5.1.0.1
erx3(config-manual-key)#
key customerASecret
erx3(config-manual-key)#
exit
erx3(config)#
ipsec key manual pre-share 5.2.0.1
erx3(config-manual-key)#
key customerASecret
erx3(config-manual-key)#
exit
erx3(config)#
ipsec key manual pre-share 5.1.0.2
erx3(config-manual-key)#
key customerBSecret
erx3(config-manual-key)#
exit
erx3(config)#
ipsec key manual pre-share 5.2.0.2
erx3(config-manual-key)#
key customerBSecret
erx3(config-manual-key)#
exit
3.
On erx1, create two IPSec tunnels, one to carry customer A's traffic and another
to carry customer B's traffic. You must create each pair of tunnels in the virtual
routers where the IP interfaces reaching those customers are defined. Create the
endpoints for the tunnels in the ISP default virtual router.
Virtual router A:
erx1(config)#
virtual-router vrA
erx1:vrA(config)#
Tunnel from Ottawa to Boston on virtual router A:
erx1:vrA(config)#
interface tunnel ipsec:Aottawa2boston transport-virtual-router
default
erx1:vrA(config-if)#
tunnel transform-set customerAprotection
erx1:vrA(config-if)#
tunnel local-identity subnet 10.1.0.0 255.255.0.0
erx1:vrA(config-if)#
tunnel peer-identity subnet 10.3.0.0 255.255.0.0
erx1:vrA(config-if)#
tunnel source 5.1.0.1
erx1:vrA(config-if)#
tunnel destination 5.3.0.1
erx1:vrA(config-if)#
ip address 10.3.0.0 255.255.0.0
erx1:vrA(config-if)#
exit
Tunnel from Ottawa to Boca on virtual router A:
erx1:vrA(config)#
interface tunnel ipsec:Aottawa2boca transport-virtual-router
default
erx1:vrA(config-if)#
tunnel transform-set customerAprotection
erx1:vrA(config-if)#
tunnel local-identity subnet 10.1.0.0 255.255.0.0
erx1:vrA(config-if)#
tunnel peer-identity subnet 10.2.0.0 255.255.0.0
erx1:vrA(config-if)#
tunnel source 5.1.0.1
erx1:vrA(config-if)#
tunnel destination 5.2.0.1
erx1:vrA(config-if)#
ip address 10.2.0.0 255.255.0.0
erx1:vrA(config-if)#
exit
Configuration Examples
■
165
Chapter 5: Configuring IPSec
Summary of Contents for JUNOSE 11.0.X IP SERVICES
Page 6: ...vi...
Page 8: ...viii JUNOSe 11 0 x IP Services Configuration Guide...
Page 18: ...xviii Table of Contents JUNOSe 11 0 x IP Services Configuration Guide...
Page 20: ...xx List of Figures JUNOSe 11 0 x IP Services Configuration Guide...
Page 22: ...xxii List of Tables JUNOSe 11 0 x IP Services Configuration Guide...
Page 28: ...2 Chapters JUNOSe 11 0 x IP Services Configuration Guide...
Page 138: ...112 Monitoring J Flow Statistics JUNOSe 11 0 x IP Services Configuration Guide...
Page 286: ...260 Monitoring IP Tunnels JUNOSe 11 0 x IP Services Configuration Guide...
Page 312: ...286 Monitoring IP Reassembly JUNOSe 11 0 x IP Services Configuration Guide...
Page 357: ...Part 2 Index Index on page 333 Index 331...
Page 358: ...332 Index JUNOSe 11 0 x IP Services Configuration Guide...