Defining the Tunnel MTU
The
tunnel mtu
command configures the maximum transmission unit size for the
tunnel.
tunnel mtu
■
Use to configure the maximum transmission unit size for the tunnel.
■
Example
host1(config-ipsec-tunnel-profile)#
tunnel mtu 3000
■
Use the
no
version to restores the default value, an MTU size of 1400 bytes.
■
See tunnel mtu.
Defining IKE Policy Rules for IPSec Tunnels
This section describes enhancements to some IKE policy rule commands to support
dynamic IPSec subscribers.
Specifying a Virtual Router for an IKE Policy Rule
The
ip address virtual-router
command enables an IKE policy rule to limit its scope
to a specific local IP address on a specific virtual router. When enabled, this limitation
ensures that this policy rule is evaluated for IKE security association evaluations for
only the specified IP address and virtual router.
When initiating and responding to an IKE SA exchange, the router evaluates the
possible policy rules as follows:
■
If an IP-address-specific IKE policy rule refers to the local IP address and virtual
router for this exchange, the router evaluates this policy rule before any
non-IP-address-specific IKE policy rules. If more than one IP-address-specific IKE
policy rule exists, the router evaluates the policy rule with the lowest priority
number first and then evaluates the policy rule with the next highest priority
number and so on.
■
If no IP-address-specific IKE policy rule refers to the local IP address and virtual
router for this exchange, the router evaluates all non-IP-address-specific IKE
policy rules in the normal IKE policy rule evaluation order.
You can define an IKE policy rule without specifying an IP address or virtual router
(the default). When not specifically configured, the IKE policy rule remains valid for
any local IP address on any virtual router residing on the router.
ip address virtual-router
Defining IKE Policy Rules for IPSec Tunnels
■
189
Chapter 6: Configuring Dynamic IPSec Subscribers
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...