Understanding Ipsec Vpn For Srx Series; Understanding Chassis Cluster For Srx Series - Juniper Junos OS Getting Started Manual

For branch srx series
Hide thumbs Also See for Junos OS:
Table of Contents

Advertisement

Getting Started Guide for Branch SRX Series

Understanding IPsec VPN for SRX Series

Related
Documentation

Understanding Chassis Cluster for SRX Series

Related
Documentation
72
A virtual private network (VPN) provides a means for securely communicating between
remote computers across a public wide area network (WAN), such as the Internet. A
VPN connection can link two local area networks (LAN) or a remote dialup user and a
LAN. The traffic that flows between these two points passes through shared resources
such as routers, switches, and other network equipment that make up the public WAN.
To secure VPN communication while passing through the WAN, the two participants
create an IP Security (IPsec) tunnel.
IPsec is a suite of protocols designed to authenticate and encrypt all IP traffic between
two locations. IPsec allows trusted data to pass through networks that would otherwise
be considered insecure. An IPsec tunnel consists of a pair of unidirectional Security
Associations (SA); one at each end of the tunnel that specify the security parameter
index (SPI), destination IP address, and security protocol (Authentication Header or
Encapsulating Security Payload) employed.
Through the SA, an IPsec tunnel can provide the following security functions:
Privacy (through encryption)
Content integrity (through data authentication)
Sender authentication
VPN Feature Guide for Security Devices
Chassis clustering provides network node redundancy by grouping a pair of the same
kind of supported SRX Series into a cluster. The devices must be running Junos OS. To
form a chassis cluster, a pair of the same kind of supported SRX Series are combined to
act as a single system that enforces the same overall security. The two nodes back each
other up, with one node acting as the primary node and the other as the secondary node;
this ensures stateful failover of processes and services in the event of system or hardware
failure.
Chassis Cluster Feature Guide for Security Devices
Copyright © 2016, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

Table of Contents