host1(config-ike-policy)#
You can then set the following parameters, or use the default settings:
•
Allow aggressive mode negotiation.
host1(config-ike-policy)#
aggressive-mode
•
Specify the authentication method.
host1(config-ike-policy)#
authentication pre-share
•
Specify the encryption algorithm.
host1(config-ike-policy)#
encryption 3des
•
Assign a Diffie-Hellman group.
host1(config-ike-policy)#
group 5
•
Set the hash algorithm.
host1(config-ike-policy)#
hash md5
•
Specify the lifetime of IKE SAs created using this policy.
host1(config-ike-policy)#
lifetime 360
aggressive-mode
•
Use to enable aggressive mode negotiation for the tunnel.
•
If you specify aggressive mode negotiation, the tunnel proposes aggressive mode to
the peer in connections that the policy initiates.
•
If the peer initiates a negotiation, the tunnel accepts the negotiation if the mode
matches this policy.
•
Use the
accepted
keyword to accept aggressive mode when proposed by peers
•
Use the
requested
keyword to request aggressive mode when negotiating with peers
•
Use the
required
keyword to only request and accept aggressive mode when negotiating
with peers.
•
Example
host1(config-ike-policy)#
aggressive-mode accepted
•
Use the
no
version to set the negotiation mode to main mode.
•
See aggressive-mode.
authentication
•
Use to specify the authentication method the router uses in the IKE policy: preshared
keys or RSA signature.
•
Example
host1(config-ike-policy)#
authentication pre-share
•
Use the
no
version to restore the default, preshared keys.
•
See authentication.
149
Copyright © 2010, Juniper Networks, Inc.
Chapter 5: Configuring IPSec
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...