behavior provides better protection against a brute force attack that makes multiple,
simultaneous authentication attempts.
•
Example
host1(config-l2tp-dest-profile-host)#
single-shot-tunnel
•
Use the
no
version to restore the default behavior for L2TP/IPSec tunnels, which
disables the single-shot attribute.
•
See single-shot-tunnel.
GRE/IPSec and DVMRP/IPSec Tunnels
In GRE/IPSec or DVMRP/IPSec connections, E Series routers can act as source and
destination endpoints of the secure tunnel. Both sides of the connection run IPSec in
transport mode with Encapsulating Security Payload (ESP) encryption and authentication.
In a GRE/IPSec or DVMRP/IPSec connection, the E Series router initiates an IPSec
connection with a remote router. After establishing the IPSec connection, the E Series
router establishes a GRE or DVMRP tunnel to the remote router. The tunnel is completely
protected by the IPSec connection.
Setting Up the Secure GRE or DVMRP Connection
In Figure 29 on page 288, a secure GRE/IPSec connection is set up between two E Series
routers. To set up the secure connection:
1.
Set up the IPSec connection between the two routers. IKE signals a security
association (SA) between the two IPSec tunnel endpoints.
Two unidirectional SAs are established to secure data traffic.
2.
Set up a GRE tunnel between the two routers.
The GRE tunnel now runs over the SAs that IKE established.
Figure 29: GRE/IPSec Connection
Configuration Tasks
The main configuration tasks for setting up GRE or DVMRP over IPSec on E Series routers
are:
Copyright © 2010, Juniper Networks, Inc.
288
JunosE 11.2.x IP Services Configuration Guide
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...