host1(config)#
ipsec key manual pre-share 10.10.1.1
host1(config-manual-key)#
masked-key
AAAAGAAAAAcSAsaVQ6Qeopt2r0hX5cMO
■
There is no
no
version. To delete a key, use the
no
version of the
ipsec key
manual
command.
■
See masked-key.
Creating an IPSec Tunnel
To create an IPSec tunnel:
1.
Enter virtual router mode. Specify the VR that contains the source and destination
addresses assigned to the tunnel interface.
host1(config)#
virtual-router vrA
host1:vrA(config)#
2.
Create an IPSec tunnel, and specify the transport VR.
host1:vrA(config)#
interface tunnel ipsec:Aottawa2boston transport-virtual-router
default
host1:vrA(config-if)#
3.
Specify the IP address of this tunnel interface.
host1:vrA(config-if)#
ip address 10.3.0.0 255.255.0.0
4.
Specify the transform set that ISAKMP uses for SA negotiations.
host1:vrA(config-if)#
tunnel transform-set customerAprotection
5.
Configure the local endpoint of the tunnel.
host1:vrA(config-if)#
tunnel local-identity subnet 10.1.0.0 255.255.0.0
6.
Configure the peer endpoint of the tunnel.
host1:vrA(config-if)#
tunnel peer-identity subnet 10.3.0.0 255.255.0.0
7.
Specify an existing interface address that the tunnel uses as its source address.
host1:vrA(config-if)#
tunnel source 5.1.0.1
8.
Specify the address or identity of the tunnel destination endpoint.
host1:vrA(config-if)#
tunnel destination identity branch245.customer77.isp.net
host1:vrA(config-if)#
exit
NOTE:
FQDNs are used when tunnel destination endpoints do not have a fixed
address, as in cable and DSL environments.
Configuration Tasks
■
149
Chapter 5: Configuring IPSec
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...