•
Use to specify that a peer use a preshared key for authentication during the tunnel
establishment phase, and to display the prompt that lets you enter the preshared key.
To enter a key, use the
key
command.
•
Specify the peer by using its IP address or fully qualified domain name (FQDN).
•
FQDNs are supported only for signaled tunnels.
•
The router must be in aggressive mode to use FQDNs with preshared keys.
•
The identity string can include an optional
user@
specification preceding the FQDN.
•
You must enter this command in the virtual router context where the IP address of the
peer is defined.
•
Example 1—using an IP Address
host1(config)#
ipsec key manual pre-share ip address 10.10.1.1
host1(config-manual-key)#
•
Example 2—using an FQDN
host1(config)#
ipsec key manual pre-share identity branch245.customer77.isp.net
host1(config-manual-key)#
•
Example 3—using an FQDN with
user@
specification
host1(config)#
ipsec key manual pre-share identity
host1(config-manual-key)#
•
Use the
no
version to delete a manually configured key from the router.
•
See ipsec key manual pre-share.
ipsec lifetime
•
Use to set the global (default) lifetime in seconds or volume of traffic in kilobytes. The
IPSec lifetime applies to tunnels that do not have a tunnel lifetime defined. When either
limit is reached, the SA is renegotiated.
•
To set a lifetime for all SAs on a tunnel, use the
tunnel lifetime
command.
•
To set a lifetime for a specific SA, use “lifetime” on page 151 .
•
Example 1
host1(config)#
ipsec lifetime kilobytes 42000000
•
Example 2
host1(config)#
ipsec lifetime seconds 8600
•
Use the
no
version to restore the default values of 4294967295 kilobytes and 28800
seconds (8 hours).
•
See ipsec lifetime.
ipsec local-endpoint
Copyright © 2010, Juniper Networks, Inc.
140
JunosE 11.2.x IP Services Configuration Guide
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...