NOTE:
After you enter a preshared key, the original (unencrypted) key cannot be
retrieved. If you need to reenter the original key (for example, the system goes to
factory default and you have only the
show config
output) you can:
1.
Use the
show config
command to see the encrypted (masked) form of the key.
2.
Use the
pre-shared-masked
command to enter the masked key. The system
will behave the same as when you entered the first
pre-share
key command.
■
See pre-share.
pre-share-masked
■
Use to specify an encrypted preshared key. To obtain this key, you enter an
unencrypted key using the
pre-share
command. You then run the
show config
command, and the router displays the preshared key in encrypted form. You
enter the encrypted key using the
pre-share-masked
command.
■
The router uses the preshared key to authenticate IKE negotiations that arrive
from any remote IP address specified for this transport profile and that are
destined for any local IP address specified for this transport profile. If the remote
endpoint address is a wildcard address, this preshared key is a group preshared
key.
CAUTION:
Group preshared keys are not fully secure, and we do not recommend
using them. They are provided for trials and testing purposes, where the missed
security does not pose a risk to the provider.
■
To have preshared key authentication take place, you must also specify the IKE
policy rule as preshared by entering
authentication pre-share
in ISAKMP Policy
Configuration mode.
■
Example
host1(config-ipsec-transport-profile-local)#
pre-share-masked
AAAAGAAAAAcAAAACZquq4ABieTUBuNBELSY8b/L3CX/RcPX7
■
There is no
no
version. To remove a key, use the
no pre-share
command.
■
See pre-share-masked.
transform-set
■
Use to specify the transform set(s) that an IPSec transport connection can use
to negotiate a transform algorithm. Each transform in the set provides a different
combination of data authentication and confidentiality.
■
To display the available transform sets, issue the
transform-set ?
command.
■
Example
host1(config-ipsec-transport-profile)#
transform-set esp-3des-hmac-sha
306
■
Configuring IPSec Transport Profiles
JUNOSe 11.1.x IP Services Configuration Guide
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...