•
Set up the GRE or DVMRP tunnel, specifying the virtual router and destination address,
and enabling IPSec support. See “Configuring IP Tunnels” on page 237.
•
Set up digital certificates on the router, or configure preshared keys for IKE
authentication.
•
To set up digital certificates, see “Configuring Digital Certificates” on page 205.
•
To set up preshared keys, see “Configuring IPSec Parameters” on page 139 in
“Configuring IPSec” on page 119.
•
Create IPSec policies. See “Defining an IKE Policy” on page 148 in “Configuring IPSec”
on page 119.
•
Configure IPSec transport profiles. See “Configuring IPSec Transport Profiles” on
page 289.
Enabling IPSec Support for GRE and DVMRP Tunnels
To create GRE/IPSec and DVMRP/IPSec tunnels, use the
ipsec-transport
keyword with
the
interface tunnel
command.
interface tunnel dvmrp
interface tunnel gre
•
Use with the
ipsec-transport
keyword to create a GRE or DVMRP tunnel that is
protected with IPSec in transport mode.
NOTE:
After you create a clear GRE or DVMRP tunnel, you cannot convert it to an
IPSec-secured tunnel, or vice versa. You must delete the tunnel configuration, then
reconfigure the tunnel as the new type.
•
You can establish the tunnel on a virtual router other than the current virtual router.
•
Example
host1(config)#
interface tunnel gre:denver-tunnel-5 transport-virtual-router denver
ipsec-transport
host1(config-if)#
•
Use the no version to remove the tunnel.
•
See interface tunnel.
Configuring IPSec Transport Profiles
To configure an IPSec transport profile that will be used to secure DVMRP, GRE, or L2TP
tunnels:
1.
Create the profile.
host1(config)#
ipsec transport profile secureGre virtual-router default ip address
5.5.5.5
289
Copyright © 2010, Juniper Networks, Inc.
Chapter 12: Securing L2TP and IP Tunnels with IPSec
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...