Table 12: Supported Security Transform Combinations
(continued)
Supported Transform Combinations
Security Type
ESP-DES-MD5
ESP-DES-SHA
ESP-3DES-MD5
ESP-3DES-SHA
Data authentication and confidentiality
The ISM does not support both the ESP and AH encapsulation modes concurrently
on the same secure tunnel.
Negotiating Transforms
Inside a transform set, IPSec transforms are numbered in a priority sequence.
■
During negotiation as an initiator of the user SA, the router uses transform
number one first. If the remote system does not agree on the transform, the
router then tries number two, and so on. If both end systems do not agree on a
transform, the user SA fails and the secure IP tunnel is not established.
■
During negotiation as a responder, the router compares the proposed transform
from the remote end against each transform in the transform set. If there is no
match, the router provides a negative answer to the remote end, which can
either try another transform or give up. If no match is found, the secure IP tunnel
is not established.
Other Security Features
The following sections briefly describe other supported security features for the ERX
routers. These features include the following:
■
“IP Security Policies” on page 138
■
“ESP Processing” on page 139
■
“AH Processing” on page 139
This section also provides a pointer to the IPSec system maximums.
IP Security Policies
The ERX router does not support a systemwide SPD. Instead, the router takes
advantage of routing to forward traffic to and from a secure tunnel. The router still
applies IPSec selectors to traffic going into or coming out of a secure tunnel so that
unwanted traffic is not allowed inside the tunnel. Supported selectors include IP
addresses, subnets, and IP address ranges.
138
■
IPSec Concepts
JUNOSe 11.1.x IP Services Configuration Guide
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...