NOTE:
When the client initiates the IPSec negotiation, the router can accept
Diffie-Hellman prime modulus groups that are higher than those configured.
For additional information about PFS, see “Configuring IPSec” on page 119.
pfs group
•
Use to configure perfect forward secrecy for connections created with this IPSec tunnel
configuration profile by assigning a Diffie-Hellman prime modulus group.
•
Example
host1(config-ipsec-tunnel-profile)#
pfs group 5
•
Use the
no
version to remove PFS from the profile.
•
See pfs group.
Defining the Tunnel MTU
The
tunnel mtu
command configures the maximum transmission unit size for the tunnel.
tunnel mtu
•
Use to configure the maximum transmission unit size for the tunnel.
•
Example
host1(config-ipsec-tunnel-profile)#
tunnel mtu 3000
•
Use the
no
version to restores the default value, an MTU size of 1400 bytes.
•
See tunnel mtu.
Defining IKE Policy Rules for IPSec Tunnels
This section describes enhancements to some IKE policy rule commands to support
dynamic IPSec subscribers.
Specifying a Virtual Router for an IKE Policy Rule
The
ip address virtual-router
command enables an IKE policy rule to limit its scope to
a specific local IP address on a specific virtual router. When enabled, this limitation
ensures that this policy rule is evaluated for IKE security association evaluations for only
the specified IP address and virtual router.
When initiating and responding to an IKE SA exchange, the router evaluates the possible
policy rules as follows:
•
If an IP-address-specific IKE policy rule refers to the local IP address and virtual router
for this exchange, the router evaluates this policy rule before any
non-IP-address-specific IKE policy rules. If more than one IP-address-specific IKE policy
rule exists, the router evaluates the policy rule with the lowest priority number first and
then evaluates the policy rule with the next highest priority number and so on.
Copyright © 2010, Juniper Networks, Inc.
180
JunosE 11.2.x IP Services Configuration Guide
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...