host1:vrA(config-if)#
exit
NOTE:
FQDNs are used when tunnel destination endpoints do not have a fixed address,
as in cable and DSL environments.
9.
For manual tunnels, specify the algorithm sets and the session key used for inbound
SAs and for outbound SAs.
host1:vrA(config-if)#
tunnel session-key-inbound esp-des-hmac-md5
a7bd567917bd5679 bd5678a7bd567917bd567917bd567678
host1:vrA(config-if)#
tunnel session-key-outbound esp-3des-hmac-md5 421
567917bd567917bd567917bd545a17bd567917bd56784a7b
fda183bef567917bd567917bd567917b
10.
(Optional) Configure PFS on this tunnel.
host1:vrA(config-if)#
tunnel pfs group 5
11.
(Optional) Set the tunnel type to signaled or manual. The default is signaled.
host1:vrA(config-if)#
tunnel signaling isakmp
12.
(Optional) Set the renegotiation time of the SAs in use by this tunnel.
host1(config-if)#
tunnel lifetime seconds 48000 kilobytes 249000
13.
(Optional) Set the MTU size for the tunnel.
host1(config-if)#
tunnel mtu 2240
interface tunnel
•
Use to create or configure an IPSec tunnel interface.
•
Use the
transport-virtual-router
keyword to establish the tunnel on a virtual router
other than the current virtual router context.
•
Example
host1(config)#
interface tunnel ipsec:jak transport-virtual-router tvr041
host1(config-if)#
•
Use the
no
version to remove the tunnel.
•
See interface tunnel.
tunnel destination
Use to set the address or identity of the remote tunnel endpoint.
•
•
For signaled IPSec tunnels in cable or DSL environments, use the FQDN to identify
the remote tunnel endpoint, which does not have a fixed IP address.
•
The identity string can include an optional
user@
specification preceding the FQDN.
•
Example 1
host1(config-if)#
tunnel destination 10.10.11.12
•
Example 2
143
Copyright © 2010, Juniper Networks, Inc.
Chapter 5: Configuring IPSec
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...