CHAPTER 12
Securing L2TP and IP Tunnels with IPSec
This chapter describes how to secure generic routing encapsulation (GRE), Distance
Vector Multicast Routing Protocol (DVMRP), and Layer 2 Tunneling Protocol (L2TP)
tunnels with IP Security (IPSec) on your E Series router. It contains the following sections:
•
Overview on page 275
•
Platform Considerations on page 276
•
References on page 276
•
L2TP/IPSec Tunnels on page 277
•
GRE/IPSec and DVMRP/IPSec Tunnels on page 288
•
Configuring IPSec Transport Profiles on page 289
•
Monitoring DVMRP/IPSec, GRE/IPSec, and L2TP/IPSec Tunnels on page 294
Overview
You can provide additional security to L2TP and IP tunnels by protecting them with an
IPSec transport connection. Secure IP interfaces are virtual IP interfaces that are
configured to provide confidentiality and authentication services for the traffic flowing
through the interface; that traffic can be L2TP, GRE, and DVMRP tunnel traffic. See
“Configuring IPSec” on page 119 for detailed information about IPSec.
GRE, DVMRP, and L2TP over IPSec provide security only between tunnel endpoints; they
do not provide end-to-end security. For end-to-end security, you need additional security
for the connection beyond the router.
Tunnel Creation
ERX routers can have both unsecured GRE, DVMRP, and L2TP tunnels and tunnels that
are secured by IPSec. However, unsecured L2TP tunnels are not allowed on the ISM. You
use the following commands to create a secure tunnel:
•
L2TP tunnels—Use the
enable ipsec transport
command in the L2TP destination
profile
•
GRE and DVMRP tunnels—Use the
ipsec-transport
keyword in the
interface tunnel
command
275
Copyright © 2010, Juniper Networks, Inc.
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...