9.
For manual tunnels, specify the algorithm sets and the session key used for
inbound SAs and for outbound SAs.
host1:vrA(config-if)#
tunnel session-key-inbound esp-des-hmac-md5
a7bd567917bd5679 bd5678a7bd567917bd567917bd567678
host1:vrA(config-if)#
tunnel session-key-outbound esp-3des-hmac-md5 421
567917bd567917bd567917bd545a17bd567917bd56784a7b
fda183bef567917bd567917bd567917b
10.
(Optional) Configure PFS on this tunnel.
host1:vrA(config-if)#
tunnel pfs group 5
11.
(Optional) Set the tunnel type to signaled or manual. The default is signaled.
host1:vrA(config-if)#
tunnel signaling isakmp
12.
(Optional) Set the renegotiation time of the SAs in use by this tunnel.
host1(config-if)#
tunnel lifetime seconds 48000 kilobytes 249000
13.
(Optional) Set the MTU size for the tunnel.
host1(config-if)#
tunnel mtu 2240
interface tunnel
■
Use to create or configure an IPSec tunnel interface.
■
Use the
transport-virtual-router
keyword to establish the tunnel on a virtual
router other than the current virtual router context.
■
Example
host1(config)#
interface tunnel ipsec:jak transport-virtual-router tvr041
host1(config-if)#
■
Use the
no
version to remove the tunnel.
■
See interface tunnel.
tunnel destination
Use to set the address or identity of the remote tunnel endpoint.
■
■
For signaled IPSec tunnels in cable or DSL environments, use the FQDN to
identify the remote tunnel endpoint, which does not have a fixed IP address.
■
The identity string can include an optional
user@
specification preceding
the FQDN.
■
Example 1
host1(config-if)#
tunnel destination 10.10.11.12
■
Example 2
host1(config-if)#
tunnel destination identity branch245.customer77.isp.net
150
■
Configuration Tasks
JUNOSe 11.1.x IP Services Configuration Guide
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...