host1(config-peer-public-key)#
■
Example 2—Enables you to configure the public key for a remote peer with the
FQDN sales.company_xyz.com
host1(config)#
ipsec key pubkey-chain rsa name sales.company_xyz.com
host1(config-peer-public-key)#
■
Example 3—Enables you to configure the public key for a remote peer with the
FQDN [email protected]_xyz.com
host1(config)#
ipsec key pubkey-chain rsa name [email protected]_xyz.com
host1(config-peer-public-key)#
■
Use the
no
version to remove the peer public key from the router.
■
See ipsec key pubkey-chain rsa.
key-string
■
Use to manually enter a 1024-bit or 2048-bit public key for a remote peer with
which you want to establish IKE SAs.
■
The key string represents the public key hexadecimal data that includes the
ASN.1 object identifier and sequence tags for RSA encryption.
■
Enter an alphanumeric key string with a maximum of 1999 characters.
■
You must use the same character (for example, “ or x) at the beginning and end
of the string to delimit the key string. The delimiter character is case-sensitive
and must not occur anywhere else in the key string.
■
For information about the format of an RSA public key, see “Public Key Format”
on page 221
.
■
Example 1—Configures the public key for a remote peer with IP address
192.168.50.10, using “ (double quotation marks) as the key string delimiter
character
host1(config)#
ipsec key pubkey-chain rsa address 192.168.50.10
host1(config-peer-public-key)#
key-string "
Enter remainder of text message. End with the character '"'.
30819f30 0d06092a 864886f7 0d010101 05000381 8d003081 89028181 00d3a447
0b997844 213de4ae 13a2c09b f74051cd d404a187 c5e86867 d525cb6e 571a44f2
92bac7e8 bb282857 fb20357c d94ec241 b651596c 350dd770 6853526b c95e60c1
52ec06ce 094882a7 4a7275a6 af1b738f 29d1124d 21e49b2a 3b0b7f2f fe31f0cc
178ddbfe a587a7a9 83aa0601 e86e7de4 3ca78f60 89a758bf 4c1247ba cb020301
0001"
■
Example 2—Configures the public key for a remote peer with the FQDN
sales.company_xyz.com, using ' (single quotation mark) as the key string delimiter
character
host1(config)#
ipsec key pubkey-chain rsa name sales.company_xyz.com
host1(config-peer-public-key)#
key-string '
Enter remainder of text message. End with the character '''.
236
■
Configuring Peer Public Keys Without Digital Certificates
JUNOSe 11.0.x IP Services Configuration Guide
Содержание JUNOSE 11.0.X IP SERVICES
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 0 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 0 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 0 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 0 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 0 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 0 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 0 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 0 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 0 x IP Services Configuration Guide...