•
To have preshared key authentication take place, you must also specify the IKE policy
rule as preshared by entering
authentication pre-share
in ISAKMP Policy Configuration
mode.
•
Example
host1(config-ipsec-transport-profile-local)#
pre-share-masked
AAAAGAAAAAcAAAACZquq4ABieTUBuNBELSY8b/L3CX/RcPX7
•
There is no
no
version. To remove a key, use the
no pre-share
command.
•
See pre-share-masked.
transform-set
•
Use to specify the transform set(s) that an IPSec transport connection can use to
negotiate a transform algorithm. Each transform in the set provides a different
combination of data authentication and confidentiality.
•
To display the available transform sets, issue the
transform-set ?
command.
•
Example
host1(config-ipsec-transport-profile)#
transform-set esp-3des-hmac-sha
•
Use the
no
version to reset the transform to the default, esp-3des-hmac-sha.
•
See transform-set.
Monitoring DVMRP/IPSec, GRE/IPSec, and L2TP/IPSec Tunnels
This section contains information about troubleshooting and monitoring DVMRP/IPSec,
GRE/IPSec, and L2TP/IPSec tunnels.
System Event Logs
To troubleshoot and monitor DVMRP/IPSec, GRE/IPSec, and L2TP/IPSec tunnels, use
the following system event log:
•
itm—IPSec transport mode
For more information about using event logs, see the
JunosE System Event Logging
Reference Guide
.
show Commands
To display profile and connection information for DVMRP/IPSec, GRE/IPSec, and
L2TP/IPSec tunnels, use the following
show
commands.
show dvmrp tunnel
show gre tunnel
•
Use to display information about DVMRP or GRE tunnels.
•
If the tunnel is protected by IPSec, the
show dvmrp tunnel detail
and
show gre tunnel
detail
commands include a line indicating the IPSec transport interface. The line is not
shown for unsecured tunnels. The following is a partial display. See “Monitoring IP
Copyright © 2010, Juniper Networks, Inc.
294
JunosE 11.2.x IP Services Configuration Guide
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...