5.
Configure L2TP destination profiles. See the next section, “Enabling IPSec Support
for L2TP” on page 285.
6.
Configure NAT-T on the virtual router. See “Configuring NAT-T” on page 286.
7.
Configure single-shot L2TP/IPSec tunnels. See “Configuring Single-Shot Tunnels”
on page 287.
8.
Configure IPSec transport profiles. See “Configuring IPSec Transport Profiles” on
page 289.
Enabling IPSec Support for L2TP
To configure an L2TP destination profile:
1.
Create a destination profile that defines the location of the LAC, and access L2TP
Destination Profile Configuration mode.
host1(config)#
l2tp destination profile boston4 ip address
0.0.0.0
host1(config-l2tp-dest-profile)#
2.
Define the L2TP host profile, and enter L2TP Destination Profile Host Configuration
mode.
host1(config-l2tp-dest-profile)#
remote host default
host1(config-l2tp-dest-profile-host)#
3.
Specify that for L2TP tunnels associated with this destination profile, the router
accept only tunnels protected by IPSec.
host1(config-l2tp-dest-profile-host)#
enable ipsec-transport
4.
(Optional) Assign a profile name for a remote host.
host1(config-l2tp-dest-profile-host)#
profile georgeProfile1
5.
Specify the local IP address to be used in any packets sent to the LAC.
host1(config-l2tp-dest-profile-host)#
local ip address 10.0.0.1
For information about other L2TP destination profile commands, see LNS Configuration
Prerequisites.
enable ipsec-transport
•
Use to specify that the router accept only L2TP tunnels protected by an IPSec transport
connection.
•
Example
host1(config-l2tp-dest-profile-host)#
enable ipsec-transport
•
Use the
no
version to disable IPSec transport mode.
•
See enable ipsec-transport.
l2tp destination profile
285
Copyright © 2010, Juniper Networks, Inc.
Chapter 12: Securing L2TP and IP Tunnels with IPSec
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...