•
Use to specify in the ISAKMP/IKE policy that the router uses the RSA signature
authentication method for IKE negotiations.
•
Example
host1(config-ike-policy)#
authentication rsa-sig
•
Use the
no
version to restore the default authentication method, preshared keys.
•
See authentication.
ipsec ike-policy-rule
•
Use to access IPSec IKE Policy Configuration mode to define an ISAKMP/IKE policy.
•
For information about how to use this command, see “ipsec ike-policy-rule” on page 217
.
•
Example
host1(config)#
ipsec ike-policy-rule 2
host1(config-ike-policy)#
•
Use the
no
version to remove policies. If you do not include a priority number with the
no
version, all policies are removed.
•
See ipsec ike-policy-rule.
ipsec key generate
•
Use to generate a 1024-bit or 2048-bit RSA key pair.
•
Example
host1(config)#
ipsec key generate rsa 2048
Please wait.................................................
..........................
IPsec Generate Keys complete
•
There is no
no
version. To remove a key pair, use the
ipsec key zeroize
command.
•
See ipsec key generate.
ipsec key pubkey-chain rsa
•
Use to access IPSec Peer Public Key Configuration mode to configure the public key
for a remote peer with which you want to establish IKE SAs.
•
The
ipsec key pubkey-chain rsa
command enables you to manually enter the public
key data for the remote peer without having to obtain a digital certificate.
•
To specify the IP address of the remote peer associated with the public key, use the
address
keyword followed by the IP address, in 32-bit dotted decimal format.
•
To specify the identity of the remote peer associated with the public key, use the
name
keyword followed by either:
•
The fully qualified domain name (FQDN)
•
The FQDN preceded by an optional
user
@ specification; this is also referred to as
user FQDN format
Copyright © 2010, Juniper Networks, Inc.
226
JunosE 11.2.x IP Services Configuration Guide
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...