Chapter 12
Securing L2TP and IP Tunnels with IPSec
This chapter describes how to secure generic routing encapsulation (GRE), Distance
Vector Multicast Routing Protocol (DVMRP), and Layer 2 Tunneling Protocol (L2TP)
tunnels with IP Security (IPSec) on your E Series router. It contains the following
sections:
■
Overview on page 287
■
Platform Considerations on page 288
■
References on page 288
■
L2TP/IPSec Tunnels on page 289
■
GRE/IPSec and DVMRP/IPSec Tunnels on page 300
■
Configuring IPSec Transport Profiles on page 302
■
Monitoring DVMRP/IPSec, GRE/IPSec, and L2TP/IPSec Tunnels on page 307
Overview
You can provide additional security to L2TP and IP tunnels by protecting them with
an IPSec transport connection. Secure IP interfaces are virtual IP interfaces that are
configured to provide confidentiality and authentication services for the traffic flowing
through the interface; that traffic can be L2TP, GRE, and DVMRP tunnel traffic. See
“Configuring IPSec” on page 125 for detailed information about IPSec.
GRE, DVMRP, and L2TP over IPSec provide security only between tunnel endpoints;
they do not provide end-to-end security. For end-to-end security, you need additional
security for the connection beyond the router.
Tunnel Creation
ERX routers can have both unsecured GRE, DVMRP, and L2TP tunnels and tunnels
that are secured by IPSec. However, unsecured L2TP tunnels are not allowed on the
ISM. You use the following commands to create a secure tunnel:
■
L2TP tunnels—Use the
enable ipsec transport
command in the L2TP destination
profile
■
GRE and DVMRP tunnels—Use the
ipsec-transport
keyword in the
interface
tunnel
command
Overview
■
287
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...