Configuring The Description For An Ipsec Proposal; Configuring The Encryption Algorithm For An Ipsec Proposal; Configuring The Lifetime For An Ipsec Sa; Configuring The Protocol For A Dynamic Sa - Juniper ACX1000 Configuration Manual

Junos os; acx series universal access router
Hide thumbs Also See for ACX1000:
Table of Contents

Advertisement

Configuring the Description for an IPsec Proposal

Configuring the Encryption Algorithm for an IPsec Proposal

Configuring the Lifetime for an IPsec SA

Configuring the Protocol for a Dynamic SA

Copyright © 2017, Juniper Networks, Inc.
To specify an optional text description for an IPsec proposal, include the
statement at the
[edit services ipsec-vpn ipsec proposal proposal-name]
[edit services ipsec-vpn ipsec proposal proposal-name]
description description;
To configure encryption algorithm for an IPsec proposal, include the
statement at the
[edit services ipsec-vpn ipsec proposal proposal-name]
[edit services ipsec-vpn ipsec proposal proposal-name]
encryption-algorithm algorithm;
ACX Series routers support Advanced Encryption Standard (AES) 128-bit encryption
algorithm.
When a dynamic IPsec SA is created, two types of lifetimes are used: hard and soft. The
hard lifetime specifies the lifetime of the SA. The soft lifetime, which is derived from the
hard lifetime, informs the IPsec key management system that the SA is about to expire.
This allows the key management system to negotiate a new SA before the hard lifetime
expires.
To configure the hard lifetime value, include the
the number of seconds at the
hierarchy level:
[edit services ipsec-vpn ipsec proposal proposal-name]
lifetime-seconds seconds;
The default lifetime is 28,000 seconds. The range is from 180 through 86,400 seconds.
The soft lifetime values are as follows:
Initiator: Soft lifetime = Hard lifetime – 135 seconds.
Responder: Soft lifetime = Hard lifetime – 90 seconds.
The
protocol
statement sets the protocol for a dynamic SA. IPsec uses ESP protocol to
protect IP traffic. The ESP protocol can support authentication, encryption, or both.
To configure the protocol for a dynamic SA, include the
esp
at the
[edit services ipsec-vpn ipsec proposal proposal-name]
[edit services ipsec-vpn ipsec proposal proposal-name]
protocol esp;
lifetime-seconds
[edit services ipsec-vpn ipsec proposal proposal-name]
protocol
Chapter 33: Configuring IPsec
description
hierarchy level:
encryption-algorithm
hierarchy level:
statement and specify
statement and specify
hierarchy level:
1099

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Acx5048Acx5096Acx500Acx1100Acx2000Acx2100 ... Show all

Table of Contents