erx3(config)#
virtual-router vrB
erx3:vrB(config)#
Tunnel from Boston to Ottawa on virtual router B:
erx3:vrB(config)#
interface tunnel ipsec:Bboston2ottawa transport-virtual-router
default
erx3:vrB(config-if)#
tunnel transform-set customerBprotection
erx3:vrB(config-if)#
tunnel local-identity subnet 10.3.0.0 255.255.0.0
erx3:vrB(config-if)#
tunnel peer-identity subnet 10.1.0.0 255.255.0.0
erx3:vrB(config-if)#
tunnel source 5.3.0.1
erx3:vrB(config-if)#
tunnel destination 5.1.0.1
erx3:vrB(config-if)#
ip address 10.1.0.0 255.255.0.0
erx3:vrB(config-if)#
exit
Tunnel from Boston to Boca on virtual router B:
erx3:vrB(config)#
interface tunnel ipsec:Bboston2boca transport-virtual-router
default
erx3:vrB(config-if)#
tunnel transform-set customerBprotection
erx3:vrB(config-if)#
tunnel local-identity subnet 10.3.0.0 255.255.0.0
erx3:vrB(config-if)#
tunnel peer-identity subnet 10.2.0.0 255.255.0.0
erx3:vrB(config-if)#
tunnel source 5.3.0.1
erx3:vrB(config-if)#
tunnel destination 5.2.0.1
erx3:vrB(config-if)#
ip address 10.2.0.0 255.255.0.0
erx3:vrB(config-if)#
exit
The configuration is complete. Customer A's traffic and customer B's traffic can flow
through the public, or untrusted, IP network inside a tunnel, where each packet is encrypted
and authenticated.
Monitoring IPSec
This section contains information about troubleshooting and monitoring IPSec.
System Event Logs
To troubleshoot and monitor IPSec, use the following system event logs:
•
auditIpsec—Lower layers of IKE SA negotiations
•
ikepki—Upper layers of IKE SA negotiations
•
stTunnel—Secure tunnel interface
For more information about using event logs, see the
JunosE System Event Logging
Reference Guide
.
show Commands
To view your IPSec configuration and to monitor IPSec tunnels and statistics, use the
following
show
commands.
show ipsec ike-policy-rule
show ike policy-rule
Copyright © 2010, Juniper Networks, Inc.
160
JunosE 11.2.x IP Services Configuration Guide
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...