Tunnels” on page 244 in “Configuring IP Tunnels” on page 237 for full descriptions of the
commands.
•
Example
host1#
show gre tunnel detail
Tunnel operational configuration
Tunnel name is 'vr1'
Tunnel mtu is '10240'
Tunnel source address is '10.0.0.2'
Tunnel destination address is '10.0.0.1'
Tunnel transport virtual router is vr1
Tunnel checksum option is disabled
Tunnel up/down trap is enabled
Tunnel server location is 4/0
Tunnel secured by ipsec transport interface 1
Tunnel administrative state is up
. . .
•
See show dvmrp tunnel.
•
See show gre tunnel.
show ipsec ike-sa
show ike sa
NOTE:
The
show ipsec ike-sa
command replaces the
show ike sa
command, which
may be removed completely in a future release.
•
Use to display IKE phase 1 SAs running on the router.
•
When NAT-T is enabled on both the client PC and the E Series router, and the router
has negotiated NAT-T as part of the IKE SA, the local UDP port number displayed in
the Local:Port column is typically 4500. When NAT-T is disabled or not supported on
one or both sides of the IKE SA negotiation, the local UDP port number is 500. (See
the example under Field Descriptions for more information.)
•
Field descriptions
•
Local:Port—Local IP address and UDP port number of phase 1 negotiation
•
Remote:Port—Remote IP address and UDP port number of phase 1 negotiation
•
Time(Sec)—Time remaining in phase 1 lifetime, in seconds
•
State—Current state of the phase 1 negotiation. Corresponds to the messaging state
in the main mode and aggressive mode negotiations. Possible states are:
•
AM_SA_I—Initiator has sent initial aggressive mode SA payload and key exchange
to the responder
•
AM_SA_R—Responder has sent aggressive mode SA payload and key exchange
to the initiator
•
AM_FINAL_I—Initiator has finished aggressive mode negotiation
295
Copyright © 2010, Juniper Networks, Inc.
Chapter 12: Securing L2TP and IP Tunnels with IPSec
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...