Setting Up the Secure GRE or DVMRP Connection
In Figure 29 on page 301, a secure GRE/IPSec connection is set up between two E
Series routers. To set up the secure connection:
1.
Set up the IPSec connection between the two routers. IKE signals a security
association (SA) between the two IPSec tunnel endpoints.
Two unidirectional SAs are established to secure data traffic.
2.
Set up a GRE tunnel between the two routers.
The GRE tunnel now runs over the SAs that IKE established.
Figure 29: GRE/IPSec Connection
Configuration Tasks
The main configuration tasks for setting up GRE or DVMRP over IPSec on E Series
routers are:
■
Set up the GRE or DVMRP tunnel, specifying the virtual router and destination
address, and enabling IPSec support. See “Configuring IP Tunnels” on page 245.
■
Set up digital certificates on the router, or configure preshared keys for IKE
authentication.
■
To set up digital certificates, see “Configuring Digital Certificates” on page 213.
■
To set up preshared keys, see “Configuring IPSec Parameters” on page 146
in “Configuring IPSec” on page 125.
■
Create IPSec policies. See “Defining an IKE Policy” on page 156 in “Configuring
IPSec” on page 125.
■
Configure IPSec transport profiles. See “Configuring IPSec Transport Profiles”
on page 302.
Enabling IPSec Support for GRE and DVMRP Tunnels
To create GRE/IPSec and DVMRP/IPSec tunnels, use the
ipsec-transport
keyword
with the
interface tunnel
command.
interface tunnel dvmrp
GRE/IPSec and DVMRP/IPSec Tunnels
■
301
Chapter 12: Securing L2TP and IP Tunnels with IPSec
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...