nonvolatile memory. Access to the private key is never given, not even to a system
administrator or to a network management system.
The public key is used in either of the following scenarios:
•
A network administration system or system administrator can retrieve it so that it can
be entered into remote security gateways with which the system needs to establish
an IKE SA.
•
It can be given to CAs so that they can properly sign it. From there, the public key is
distributed to remote security gateways that can handle a PKI.
The public/private key pair as provided by the system supports the RSA standard (512,
1024, or 2048 bits).
The public/private key pair is a global system attribute, regardless of how many ISMs
exist in the system. Only one set of keys is available at any given time.
Configuration Tasks
This section explains the steps to configure an IPSec license and IPSec parameters,
create an IPSec tunnel, and define an ISAKMP/IKE policy. The next section contains
configuration examples.
Configuring an IPSec License
By default, and with no IPSec tunnel license, you can configure up to 10 IPSec tunnels
on an ERX router. However, you can purchase licenses that support the following IPSec
tunnel maximums:
•
1000
•
2000
•
4000
•
8000
•
16000
•
32000
The number of additional tunnels is independent of the number of ISMs installed in the
router. However, the router chassis enforces the following tunnel limits:
•
SRP 10G – 10,000
•
SRP 40G – 20,000
license ipsec-tunnels
Copyright © 2010, Juniper Networks, Inc.
138
JunosE 11.2.x IP Services Configuration Guide
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...