■
manual
—Specifies that security parameters and keys are configured manually
■
Example
host1(config-if)#
tunnel signaling manual
■
Use the
no
version to restore the default value,
isakmp
.
■
See tunnel signaling.
tunnel source
■
Use to specify an existing interface address that serves as the tunnel's source
address.
■
For signaled IPSec tunnels in cable or DSL environments, you can optionally use
an FQDN to identify the tunnel endpoint.
■
Example
host1(config-if)#
tunnel source 10.10.2.8
■
Use the
no
version to remove the tunnel source.
■
See tunnel source.
tunnel transform-set
■
Use to specify the transform set that ISAKMP uses during SA negotiations on this
tunnel. You create transform sets using “ipsec transform-set” on page 148 .
■
Example
host1(config-if)#
tunnel transform-set espSet
■
Use the no version to remove the transform set from a tunnel.
■
See tunnel transform-set.
Configuring DPD and IPSec Tunnel Failover
You can use the
ipsec option dpd
command to enable dead peer detection (DPD)
on the router. DPD is also known as IKE keepalive. If an IPSec tunnel destination
backup is configured, the router redirects traffic to the alternate destination when
DPD detects a disconnection between the E Series router and the regular tunnel
destination. See “tunnel destination backup” on page 155 .
To enable DPD and create an alternate IPSec tunnel destination for failover:
1.
Enable DPD on the router.
host1(config)#
ipsec option dpd
2.
Enter virtual router mode. Specify the VR that contains the source and destination
addresses assigned to the tunnel interface (that is, the transport virtual router
context).
154
■
Configuration Tasks
JUNOSe 11.1.x IP Services Configuration Guide
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...