■
One IPSec license
If either license is unavailable, the router denies access to the subscriber.
Inherited Subscriber Functionality
Dynamic IPSec subscribers inherit much of the built-in AAA subscriber management
functionality. This functionality includes the following:
■
AAAA subscriber management commands
■
DNS (primary and secondary)
■
WINS (primary and secondary)
■
Session timeout
■
Accounting features (interval, duplication, immediate update, broadcasting,
Acct-stop)
■
Duplicate address checking
■
IP address pools
■
Per virtual-router subscriber limit
■
Policies
■
Packet mirroring
For additional information on AAA functionality, see
JUNOSe Broadband Access
Configuration Guide
.
Using IPSec Tunnel Profiles
IPSec tunnel profiles serve the following purposes in the configuration of dynamic
IPSec subscribers:
■
Controlling which connecting user, based on the IKE identification, belongs to
a given profile. Profile settings falling in this category include the following:
■
IKE identities from peers that can use this profile. These identities include
IP addresses, domain names, and E-mail addresses. In addition, distinguished
names that use X.509 certificates are permitted.
■
The router IKE identity.
■
Terminating extraneous security and IP profile settings that exist after a subscriber
is mapped to an IPSec tunnel. These settings include the following:
■
Maximum number of subscribers that this profile can terminate
■
AAA domain suffix intended for the username (helping to bridge users from
a given IPSec tunnel profile to an AAA domain map)
■
Phase 2 SA selectors for use in phase 2 SA exchanges
■
IP profiles intended for users logging in using this profile (helping to bridge
users from a given IPSec tunnel profile to an IP profile)
Overview
■
179
Chapter 6: Configuring Dynamic IPSec Subscribers
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...