Use to control how the router handles CRLs during negotiation of IKE phase 1
signature authentication. Specify one of the following keywords:
■
■
ignored
—Allows negotiations to succeed even if a CRL is invalid or the peer's
certificate appears in the CRL; this is the most lenient setting
■
optional
—If the router finds a valid CRL, it uses it; this is the default setting
■
required
—Requires a valid CRL; either the certificates that belong to the E
Series router or the peer must not appear in the CRL; this is the strictest
setting
■
Example
host1(config)#
ipsec crl ignored
■
Use the
no
version to return the CRL setting to the default, optional.
NOTE:
This command replaces “ike crl” on page 223 , which may be removed
completely in a future release.
■
See ipsec crl.
ipsec identity
■
Use to enter IPSec Identity Configuration mode in which you can specify
information that the router uses in certificate requests and during negotiations
with its peers.
■
Example
host1(config)#
ipsec identity
host1(config-ipsec-identity)#
■
Use the
no
version to remove the identity configuration.
■
See ipsec identity.
ipsec ike-policy-rule
■
Use to define an ISAKMP/IKE policy.
■
When you enter the command, you include a number that identifies the policy
and assigns a priority to the policy. You can number policies in the range
1–10000, with 1 having the highest priority.
■
Example
host1(config)#
ipsec ike-policy-rule 3
host1(config-ike-policy)#
■
Use the
no
version to remove policies. If you do not include a priority number
with the
no
version, all policies are removed.
Configuring Digital Certificates Using the Offline Method
■
225
Chapter 8: Configuring Digital Certificates
Содержание JUNOSE 11.0.X IP SERVICES
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 0 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 0 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 0 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 0 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 0 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 0 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 0 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 0 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 0 x IP Services Configuration Guide...