extended-authentication
•
Use to specify the extended user authentication protocol for use during the extended
user authentication protocol exchange. This command can also enable or disable the
reauthentication option (a subsequent authentication procedure).
•
The
re-authenticate
keyword enables the reauthentication option (a subsequent
authentication procedure).
•
The
skip-peer-config
keyword disables the router from configuring peer IP
characteristics.
•
Example
host1(config-ipsec-tunnel-profile)#
extended-authentication chap
•
Use the
no
version to reset the extended authentication to the default protocol, pap.
•
See extended-authentication.
Specifying IPSec Security Association Transforms
The
transform
command specifies the IPSec transforms that IPSec SA negotiations can
use for this profile. The router accepts the first transform proposed by a client that
matches one of the transforms specified by this command. During an IPSec SA exchange
with a client, the router proposes all transforms specified by this command and one is
accepted by the client.
NOTE:
You can specify up to six transform algorithms for this profile.
For additional information about transforms and transform sets, see “Configuring IPSec”
on page 119.
transform
•
Use to specify the eligible transforms for this profile for IPSec security association
negotiations.
•
Example
host1(config-ipsec-tunnel-profile)#
transform ah-hmac-md5
•
Use the
no
version to reset the transform to the default, esp-3des-sha1.
•
See transform.
Specifying IPSec Security Association PFS and DH Group Parameters
The
pfs group
command specifies the IPSec SA perfect forward secrecy (PFS) option
and Diffie-Hellman prime modulus group that IPSec SA negotiations can use for this
profile.
179
Copyright © 2010, Juniper Networks, Inc.
Chapter 6: Configuring Dynamic IPSec Subscribers
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...