Table 10: Security Parameters per IPSec Policy Type
Signaled
Manual
Security Parameter
Required
Required
Operational VR
Required
Required
Transport VR
Optional
Optional
Perfect forward secrecy
Optional
Optional
Lifetime
Not applicable
Required
Inbound and outbound SAs
Required
Required
Transform set
Operational Virtual Router
The operational VR for a secure IP tunnel is the VR in which a secure IP tunnel exists.
The IP address and mask associated with a secure IP interface exist only within the
operational VR under which the interface is declared. The VR defines the network
prefix, which is reachable through the logical IP interface.
A secure IP tunnel is always a member of one and only one operational VR. Therefore,
the operational VR attributes are mandatory for any secure tunnel. These attributes
include:
■
IP address and mask
■
Virtual router on which the secure IP interface exists
Transport Virtual Router
The transport VR for a secure IP tunnel is the VR in which both of the secure tunnel
endpoints, the source and destination, are routable addresses. Normally, the transport
VR is the default ISP routing infrastructure on top of which VPNs are provisioned.
The IPSec Service module (ISM) is a security gateway and, as such, is one of the
endpoints for secure tunnels. The tunnel endpoints are the tunnel
source
and the
tunnel
destination
IP addresses. For IKE signaled IPSec tunnels, you can use the fully
qualified domain name (FQDN) instead of the IP address to identify the tunnel
endpoints. You typically use this feature to identify the tunnel destination endpoint
in DSL and broadband environments. See “Transport VR Definitions with an FQDN”
on page 133 in this section.
■
The tunnel source IP address must be one of the local IP addresses configured
on the router.
■
The tunnel destination address must be a routable IP address within the transport
VR routing tables.
132
■
IPSec Concepts
JUNOSe 11.0.x IP Services Configuration Guide
Содержание JUNOSE 11.0.X IP SERVICES
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 0 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 0 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 0 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 0 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 0 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 0 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 0 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 0 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 0 x IP Services Configuration Guide...