■
Use to enable the router to send an invalid cookie notification to an IKE peer
when the router does not recognize the initiator-responder cookie pair.
■
Example
host1(config)#
ipsec option tx-invalid-cookie
■
Use the
no
version to restore the default, disabling the ability to send an invalid
cookie notification.
■
See ipsec option tx-invalid-cookie.
Configuration Examples
This section contains examples of two IPSec applications. The first example shows
a customer who replaces a leased line network with an IPSec network that allows
the company to connect its corporate locations over the Internet. The second example
provides leased line replacement to two customers who use address schemes in the
same range.
Configuration Notes
Both the local and remote identities shown in these examples serve two purposes:
■
They identify multiple IPSec tunnels between the same endpoints.
■
They filter traffic going into and coming out of the tunnels so that it is within the
specified range. If the configuration requires that only one IPSec tunnel exists
between two endpoints and no traffic filtering is required, you can omit the
tunnel local-identity
and
tunnel peer-identity
commands.
Example 1
In Figure 15 on page 160 customer A is using Frame Relay to connect its corporate
offices in three cities: Boston, Ottawa, and Boca.
Figure 15: Customer A's Corporate Frame Relay Network
Customer A hires ISP-X to provide a leased line replacement over an IP infrastructure
using IPSec. ISP-X can offer a replacement for long-haul Frame Relay links by creating
IPSec tunnels to carry customer A's traffic securely between the sites over the public
or ISP-provided IP network. This alternative costs only a fraction of the price of the
Frame Relay links. Figure 16 on page 161 shows the connectivity scheme.
160
■
Configuration Examples
JUNOSe 11.1.x IP Services Configuration Guide
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...