•
Provides IPSec filtering based on the received IP address (the NAT public IP
address), rather than filtering based on the negotiated IKE identities.
•
Example
host1(config-ipsec-transport-profile)#
application gre dvmrp l2tp
•
Use the
no
version to return to the default application type, L2TP.
•
See application.
ipsec transport profile
Use to create an IPSec transport profile and to enter IPSec Transport Profile
Configuration mode. To create a new profile, you must include the following keywords:
•
•
virtual-router—
Name of the virtual router on which you want to create the profile
•
ip address
—Remote endpoint for the IPSec transport connection.
For L2TP/IPSec connections, you can enter a fixed IP address or the wildcard address,
0.0.0.0. If you use the wildcard address, the profile accepts any remote client
connection, which is a typical scenario for secure remote access.
For GRE/IPSec and DVMRP/IPSec connections, you must enter a fixed address; the
0.0.0.0 wildcard address is not accepted and will return an error.
•
Example
host1(config)#
ipsec transport profile secureL2tp virtual-router default ip address
5.5.5.5
host1(config-ipsec-transport-profile)#
•
Use the
no
version to delete the profile.
•
See ipsec transport profile.
lifetime
•
Use to set a lifetime range for the IPSec connection in volume of traffic or in seconds
or both.
•
If the PC client offers a lifetime within this range, the router accepts the offer. If the PC
client offers a lifetime outside this range, the router rejects the connection.
•
Example
host1(config-ipsec-transport-profile)#
lifetime seconds 900 86400 kilobytes 100000
4294967295
•
Use the
no
version to restore the default values, 100000–4294967295 KB and
900–86400 seconds (0.25–24 hours).
•
See lifetime.
local ip address
291
Copyright © 2010, Juniper Networks, Inc.
Chapter 12: Securing L2TP and IP Tunnels with IPSec
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...