•
Use to define an IKE policy.
•
When you enter the command, you include a number that identifies the policy and
assigns a priority to the policy. You can number policies in the range 1–10000, with 1
having the highest priority.
•
You can add up to 10 IKE policies per router.
•
Example
host1(config)#
ipsec ike-policy-rule 3
host1(config-ike-policy)#
•
Use the
no
version to remove policies. If you do not include a priority number with the
no
version, all policies are removed.
•
See ipsec ike-policy-rule.
•
See ipsec isakmp-policy-rule.
lifetime
•
Use to specify the lifetime of IKE SAs.
•
The range is 60–86400 seconds.
host1(config-ike-policy)#
lifetime 360
•
Use the
no
version to reset the SA lifetime to the default, 28800 seconds.
•
See lifetime.
Refreshing SAs
To refresh ISAKMP/IKE or IPSec SAs:
host1(config)#
ipsec clear sa tunnel ipsec:Aottawa2boca phase 2
ipsec clear sa
•
Use to refresh ISAKMP/IKE or IPSec SAs.
•
To reinitialize all SAs, use the
all
keyword.
•
To reinitialize SAs on a specific tunnel, use the
tunnel
keyword.
•
To reinitialize SAs on tunnels that are in a specific state, use the
state
keyword.
•
To specify the type of SA to be reinitialized, ISAKMP/IKE or IPSEC, use the
phase
keyword.
•
Example
host1(config)#
ipsec clear sa all phase 2
•
There is no
no
version.
•
See ipsec clear sa.
151
Copyright © 2010, Juniper Networks, Inc.
Chapter 5: Configuring IPSec
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...