■
Use to override the peer identity (phase 2 identity) used for IPSec security
association negotiations. For IPSec negotiations to succeed, the local and peer
identities at one end of the tunnel must match the peer and local identities at
the other end (respectively).
■
Example
host1(config-ipsec-tunnel-profile)#
peer ip identity address 10.227.1.2
■
Use the
no
version to restore the default value, the internal IP address allocated
for the subscriber.
■
See peer ip identity.
Specifying an IP Profile for IP Interface Instantiations
The
ip profile
command specifies the IP profile that is passed from the IPSec layer
to the IP layer upon request for upper layer instantiation.
ip profile
■
Use to specify the IP profile that the IPSec layer passes on to the IP layer upon
request for upper-layer instantiation.
■
Example
host1(config-ipsec-tunnel-profile)#
ip profile ipProfile1
■
Use the
no
version to remove the association with this profile.
■
See ip profile.
Defining the Server IP Address
The
local ip address
command defines the specified local IP address as the server
address. The router monitors UDP port 500 for incoming login requests (that is, IKE
SA negotiations) from users.
NOTE:
This address is typically made public to all users trying to connect to a VPN
on this router.
This command enables you to optionally set a global preshared key for the specified
server address. When using global preshared keys, keep the following in mind:
■
Global preshared keys enable a group of users to share a single authentication
key, simplifying the administrative job of setting up keys for multiple users.
■
Specific keys for individual users have higher priority than global keys. If both
individual and global keys are configured, the individual that also has a specific
key must use that key or authentication fails.
Configuring IPSec Tunnel Profiles
■
185
Chapter 6: Configuring Dynamic IPSec Subscribers
Содержание JUNOSE 11.0.X IP SERVICES
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 0 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 0 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 0 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 0 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 0 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 0 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 0 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 0 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 0 x IP Services Configuration Guide...