CHAPTER 6
Configuring Dynamic IPSec Subscribers
This chapter describes how to securely terminate IPSec remote access subscribers. These
subscribers can reside on different VPNs and the router can support many VPNs
simultaneously. It contains the following sections:
•
Overview on page 169
•
Platform Considerations on page 172
•
References on page 173
•
Creating an IPSec Tunnel Profile on page 173
•
Configuring IPSec Tunnel Profiles on page 174
•
Defining IKE Policy Rules for IPSec Tunnels on page 180
•
Monitoring IPSec Tunnel Profiles on page 181
Overview
You can use the E Series router to terminate users on multiple VPNs (that is, a private
intranet where users can log in and access private servers). For the E Series router, VPNs
appear as VRs or VRFs. Users that connect to the VPN terminate on the associated VR
or VRF. The router contains a link between the VR or VRF and the private intranet
containing the resources. This link can be a direct connection, or a tunnel (IPSec, IP-in-IP,
GRE, or MPLS). Once establishing a connection, the router can pass traffic between the
VPN and connected users.
The E Series router already supports termination of secure remote access subscribers
using L2TP and IPSec. In this model, IPSec uses transport mode to “ protect” PPP
subscribers that use L2TP tunnels as described in RFC 3193. However, because they are
handled by the PPP and L2TP application, IPSec has no direct information about the
subscribers. By terminating dynamic IPSec subscribers, the IPSec protocol manages the
subscribers completely.
Dynamic Connection Setup
Dynamic secure remote access subscribers initiate connections to the E Series router by
establishing an IPSec phase 1 security association (SA; also known as an IKE SA or P1)
with the router.
169
Copyright © 2010, Juniper Networks, Inc.
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...