Chapter 6
Configuring Dynamic IPSec Subscribers
This chapter describes how to securely terminate IPSec remote access subscribers.
These subscribers can reside on different VPNs and the router can support many
VPNs simultaneously. It contains the following sections:
■
Overview on page 177
■
Platform Considerations on page 180
■
References on page 181
■
Creating an IPSec Tunnel Profile on page 181
■
Configuring IPSec Tunnel Profiles on page 182
■
Defining IKE Policy Rules for IPSec Tunnels on page 189
■
Monitoring IPSec Tunnel Profiles on page 190
Overview
You can use the E Series router to terminate users on multiple VPNs (that is, a private
intranet where users can log in and access private servers). For the E Series router,
VPNs appear as VRs or VRFs. Users that connect to the VPN terminate on the
associated VR or VRF. The router contains a link between the VR or VRF and the
private intranet containing the resources. This link can be a direct connection, or a
tunnel (IPSec, IP-in-IP, GRE, or MPLS). Once establishing a connection, the router
can pass traffic between the VPN and connected users.
The E Series router already supports termination of secure remote access subscribers
using L2TP and IPSec. In this model, IPSec uses transport mode to “ protect” PPP
subscribers that use L2TP tunnels as described in RFC 3193. However, because they
are handled by the PPP and L2TP application, IPSec has no direct information about
the subscribers. By terminating dynamic IPSec subscribers, the IPSec protocol
manages the subscribers completely.
Dynamic Connection Setup
Dynamic secure remote access subscribers initiate connections to the E Series router
by establishing an IPSec phase 1 security association (SA; also known as an IKE SA
or P1) with the router.
After establishing a security association, the subscriber is instantiated in the IPSec
software. Following this instantiation, the router initiates the extended authentication
(Xauth) protocol exchange to invoke the user to enter a username and password.
Overview
■
177
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...