to the username. Using the default, no domain suffix, passes usernames transparently
to AAA.
domain-suffix
•
Use to specify a domain suffix that you want to append to any usernames received on
this profile.
•
Example
host1(config-ipsec-tunnel-profile)#
domain-suffix domain2
•
Use the
no
version to restore the default value, no domain suffix, and usernames are
passed transparently to AAA.
•
See domain-suffix.
Overriding IPSec Local and Peer Identities for SA Negotiations
You can use the
local ip identity
and
peer ip identity
commands to override the local
and peer identities used for SA negotiations (respectively).
local ip identity
•
Use to override the local identity (phase 2 identity) used for IPSec security association
negotiations. For IPSec negotiations to succeed, the local and peer identities at one
end of the tunnel must match the peer and local identities at the other end
(respectively).
•
Example
host1(config-ipsec-tunnel-profile)#
local ip identity range 10.30.11.1 10.30.11.50
•
Use the
no
version to restore the default value, the internal IP address allocated for
the subscriber.
•
See local ip identity.
peer ip identity
•
Use to override the peer identity (phase 2 identity) used for IPSec security association
negotiations. For IPSec negotiations to succeed, the local and peer identities at one
end of the tunnel must match the peer and local identities at the other end
(respectively).
•
Example
host1(config-ipsec-tunnel-profile)#
peer ip identity address 10.227.1.2
•
Use the
no
version to restore the default value, the internal IP address allocated for
the subscriber.
•
See peer ip identity.
Specifying an IP Profile for IP Interface Instantiations
The
ip profile
command specifies the IP profile that is passed from the IPSec layer to
the IP layer upon request for upper layer instantiation.
Copyright © 2010, Juniper Networks, Inc.
176
JunosE 11.2.x IP Services Configuration Guide
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...