Figure 16: ISP-X Uses ERX Routers to Connect Corporate Offices over the Internet
To configure the connections as shown in Figure 16 on page 161:
1.
On each ERX router, create a protection suite that provides 3DES encryption
with SHA-1 authentication on every packet.
erx1(config)#
ipsec transform-set customerAprotection esp-3des-hmac-sha
erx2(config)#
ipsec transform-set customerAprotection esp-3des-hmac-sha
erx3(config)#
ipsec transform-set customerAprotection esp-3des-hmac-sha
2.
On each ERX router, create preshared keys for the three routers to use to
authenticate each other:
erx1(config)#
ipsec key manual pre-share 100.2.0.1
erx1(config-manual-key)#
key customerASecret
erx1(config-manual-key)#
exit
erx1(config)#
ipsec key manual pre-share 100.3.0.1
erx1(config-manual-key)#
key customerASecret
erx1(config-manual-key)#
exit
erx2(config)#
ipsec key manual pre-share 100.1.0.1
erx2(config-manual-key)#
key customerASecret
erx2(config-manual-key)#
exit
erx2(config)#
ipsec key manual pre-share 100.3.0.1
erx2(config-manual-key)#
key customerASecret
erx2(config-manual-key)#
exit
erx3(config)#
ipsec key manual pre-share 100.1.0.1
erx3(config-manual-key)#
exit
erx3(config-manual-key)#
key customerASecret
erx3(config)#
ipsec key manual pre-share 100.2.0.1
erx3(config-manual-key)#
key customerASecret
erx3(config-manual-key)#
exit
3.
On erx1 create two IPSec tunnels, one to carry customer A's traffic between
Ottawa and Boston and another to carry the traffic between Ottawa and Boca:
Tunnel 1:
Configuration Examples
■
161
Chapter 5: Configuring IPSec
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...