host1(config-l2tp-dest-profile-host)#
single-shot-tunnel
5.
(Optional) Configure other attributes for the L2TP host profile.
6.
(Optional) Use the
show l2tp destination profile
command to verify configuration
of the single-shot tunnel for a particular L2TP host profile.
For information about how to use this command, see “show l2tp destination
profile” on page 313.
For information about the other commands you can use to configure L2TP destination
profiles and L2TP host profiles, see LNS Configuration Prerequisites.
single-shot-tunnel
■
Use to configure the L2TP/IPSec tunnels associated with a particular L2TP host
profile as single-shot tunnels.
■
A single-shot tunnel can carry no more than a single L2TP session for the duration
of its existence.
■
The router ignores the idle timeout period for single-shot tunnels.
■
The following characteristics apply only to secure L2TP/IPSec single-shot tunnels:
■
The underlying IPSec connection for a single-shot tunnel can carry no more
than a single L2TP tunnel for the duration of its existence.
■
The router disconnects the underlying IPSec transport connection for a
single-shot tunnel at the beginning of the destruct timeout period instead of
waiting until the destruct timeout period expires.
■
A single-shot tunnel does not persist beyond its last connected L2TP session. As
a result, using single-shot L2TP/IPSec tunnels instead of the default (standard)
tunnel behavior provides better protection against a brute force attack that makes
multiple, simultaneous authentication attempts.
■
Example
host1(config-l2tp-dest-profile-host)#
single-shot-tunnel
■
Use the
no
version to restore the default behavior for L2TP/IPSec tunnels, which
disables the single-shot attribute.
■
See single-shot-tunnel.
GRE/IPSec and DVMRP/IPSec Tunnels
In GRE/IPSec or DVMRP/IPSec connections, E Series routers can act as source and
destination endpoints of the secure tunnel. Both sides of the connection run IPSec
in transport mode with Encapsulating Security Payload (ESP) encryption and
authentication.
In a GRE/IPSec or DVMRP/IPSec connection, the E Series router initiates an IPSec
connection with a remote router. After establishing the IPSec connection, the E Series
router establishes a GRE or DVMRP tunnel to the remote router. The tunnel is
completely protected by the IPSec connection.
300
■
GRE/IPSec and DVMRP/IPSec Tunnels
JUNOSe 11.0.x IP Services Configuration Guide
Содержание JUNOSE 11.0.X IP SERVICES
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 0 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 0 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 0 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 0 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 0 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 0 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 0 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 0 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 0 x IP Services Configuration Guide...