Virtual router B:
erx1(config)#
virtual-router vrB
erx1:vrB(config)#
Tunnel from Ottawa to Boston on virtual router B:
erx1:vrB(config)#
interface tunnel ipsec:Bottawa2boston transport-virtual-router
default
erx1:vrB(config-if)#
tunnel transform-set customerBprotection
erx1:vrB(config-if)#
tunnel local-identity subnet 10.1.0.0 255.255.0.0
erx1:vrB(config-if)#
tunnel peer-identity subnet 10.3.0.0 255.255.0.0
erx1:vrB(config-if)#
tunnel source 5.1.0.2
erx1:vrB(config-if)#
tunnel destination 5.3.0.2
erx1:vrB(config-if)#
ip address 10.3.0.0 255.255.0.0
erx1:vrB(config-if)#
exit
Tunnel from Ottawa to Boca on virtual router B:
erx1:vrB(config)#
interface tunnel ipsec:Bottawa2boca transport-virtual-router
default
erx1:vrB(config-if)#
tunnel transform-set customerBprotection
erx1:vrB(config-if)#
tunnel local-identity subnet 10.1.0.0 255.255.0.0
erx1:vrB(config-if)#
tunnel peer-identity subnet 10.2.0.0 255.255.0.0
erx1:vrB(config-if)#
tunnel source 5.1.0.2
erx1:vrB(config-if)#
tunnel destination 5.2.0.2
erx1:vrB(config-if)#
ip address 10.2.0.0 255.255.0.0
erx1:vrB(config-if)#
exit
4.
On erx2, create two IPSec tunnels, one to carry customer A's traffic and another
to carry customer B's traffic. You must create each pair of tunnels in the virtual
routers where the IP interfaces reaching those customers are defined. Create the
endpoints for the tunnels in the ISP default virtual router.
Virtual router A:
erx2(config)#
virtual-router vrA
erx2:vrA(config)#
Tunnel from Boca to Ottawa on virtual router A:
erx2:vrA(config)#
interface tunnel ipsec:Aboca2ottawa transport-virtual-router
default
erx2:vrA(config-if)#
tunnel transform-set customerAprotection
erx2:vrA(config-if)#
tunnel local-identity subnet 10.2.0.0 255.255.0.0
erx2:vrA(config-if)#
tunnel peer-identity subnet 10.1.0.0 255.255.0.0
erx2:vrA(config-if)#
tunnel source 5.2.0.1
erx2:vrA(config-if)#
tunnel destination 5.1.0.1
erx2:vrA(config-if)#
ip address 10.1.0.0 255.255.0.0
erx2:vrA(config-if)#
exit
Tunnel from Boca to Boston on virtual router A:
erx2:vrA(config)#
interface tunnel ipsec:Aboca2boston transport-virtual-router
default
erx2:vrA(config-if)#
tunnel transform-set customerAprotection
erx2:vrA(config-if)#
tunnel local-identity subnet 10.2.0.0 255.255.0.0
166
■
Configuration Examples
JUNOSe 11.1.x IP Services Configuration Guide
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...