■
Use the
no
version to delete the IP address.
■
See local ip address.
pfs group
■
Use to configure perfect forward secrecy for connections created with this IPSec
transport profile.
■
Assign a Diffie-Hellman prime modulus group using one of the following
keywords:
■
1
—768-bit group
■
2
—1024-bit group
■
5
—1536-bit group
■
Example
host1(config-ipsec-transport-profile)#
pfs group 5
■
Use the
no
version to remove PFS from this profile, which is the default setting.
■
See pfs group.
pre-share
■
Use to configure an unencrypted (red) preshared key to authenticate IKE
negotiations that arrive from any remote IP address specified for this transport
profile and that are destined for the local IP address. If the remote endpoint
address is a wildcard address, this preshared key is a group preshared key.
CAUTION:
Group preshared keys are not fully secure, and we do not recommend
using them. They are provided for trials and testing purposes where the missed
security does not pose a risk to the provider.
■
To have preshared key authentication take place, you must also specify the IKE
policy rule as preshared by entering
authentication pre-share
in ISAKMP Policy
Configuration mode.
■
Example
host1(config-ipsec-transport-profile-local)#
pre-share secretforL2tp
■
Use the
no
version to remove the key.
Configuring IPSec Transport Profiles
■
305
Chapter 12: Securing L2TP and IP Tunnels with IPSec
Содержание JUNOSE 11.0.X IP SERVICES
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 0 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 0 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 0 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 0 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 0 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 0 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 0 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 0 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 0 x IP Services Configuration Guide...