erx2(config-manual-key)#
key customerASecret
erx2(config-manual-key)#
exit
erx2(config)#
ipsec key manual pre-share 5.1.0.2
erx2(config-manual-key)#
key customerBSecret
erx2(config-manual-key)#
exit
erx2(config)#
ipsec key manual pre-share 5.3.0.2
erx2(config-manual-key)#
key customerBSecret
erx2(config-manual-key)#
exit
erx3(config)#
ipsec key manual pre-share 5.1.0.1
erx3(config-manual-key)#
key customerASecret
erx3(config-manual-key)#
exit
erx3(config)#
ipsec key manual pre-share 5.2.0.1
erx3(config-manual-key)#
key customerASecret
erx3(config-manual-key)#
exit
erx3(config)#
ipsec key manual pre-share 5.1.0.2
erx3(config-manual-key)#
key customerBSecret
erx3(config-manual-key)#
exit
erx3(config)#
ipsec key manual pre-share 5.2.0.2
erx3(config-manual-key)#
key customerBSecret
erx3(config-manual-key)#
exit
3.
On erx1, create two IPSec tunnels, one to carry customer A's traffic and another to
carry customer B's traffic. You must create each pair of tunnels in the virtual routers
where the IP interfaces reaching those customers are defined. Create the endpoints
for the tunnels in the ISP default virtual router.
Virtual router A:
erx1(config)#
virtual-router vrA
erx1:vrA(config)#
Tunnel from Ottawa to Boston on virtual router A:
erx1:vrA(config)#
interface tunnel ipsec:Aottawa2boston transport-virtual-router
default
erx1:vrA(config-if)#
tunnel transform-set customerAprotection
erx1:vrA(config-if)#
tunnel local-identity subnet 10.1.0.0 255.255.0.0
erx1:vrA(config-if)#
tunnel peer-identity subnet 10.3.0.0 255.255.0.0
erx1:vrA(config-if)#
tunnel source 5.1.0.1
erx1:vrA(config-if)#
tunnel destination 5.3.0.1
erx1:vrA(config-if)#
ip address 10.3.0.0 255.255.0.0
erx1:vrA(config-if)#
exit
Tunnel from Ottawa to Boca on virtual router A:
erx1:vrA(config)#
interface tunnel ipsec:Aottawa2boca transport-virtual-router
default
erx1:vrA(config-if)#
tunnel transform-set customerAprotection
erx1:vrA(config-if)#
tunnel local-identity subnet 10.1.0.0 255.255.0.0
erx1:vrA(config-if)#
tunnel peer-identity subnet 10.2.0.0 255.255.0.0
erx1:vrA(config-if)#
tunnel source 5.1.0.1
erx1:vrA(config-if)#
tunnel destination 5.2.0.1
erx1:vrA(config-if)#
ip address 10.2.0.0 255.255.0.0
erx1:vrA(config-if)#
exit
Virtual router B:
erx1(config)#
virtual-router vrB
erx1:vrB(config)#
157
Copyright © 2010, Juniper Networks, Inc.
Chapter 5: Configuring IPSec
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...