Configuring The Description For An Ipsec Policy; Configuring Perfect Forward Secrecy; Configuring The Proposals In An Ipsec Policy - Juniper ACX1000 Configuration Manual

Junos os; acx series universal access router
Hide thumbs Also See for ACX1000:
Table of Contents

Advertisement

Configuring the Description for an IPsec Policy

Configuring Perfect Forward Secrecy

Configuring the Proposals in an IPsec Policy

Copyright © 2017, Juniper Networks, Inc.
}
This section includes the following topics related to configuring an IPsec policy:
Configuring the Description for an IPsec Policy on page 1103
Configuring Perfect Forward Secrecy on page 1103
Configuring the Proposals in an IPsec Policy on page 1103
To specify an optional text description for an IPsec policy, include the
statement at the
[edit services ipsec-vpn ipsec policy policy-name]
[edit services ipsec-vpn ipsec policy policy-name]
description description;
PFS provides additional security by means of a Diffie-Hellman shared secret value. With
PFS, if one key is compromised, previous and subsequent keys are secure because they
are not derived from previous keys. This statement is optional.
To configure PFS, include the
Diffie-Hellman group at the
level:
[edit services ipsec-vpn ipsec policy policy-name]
perfect-forward-secrecy {
keys (group1 | group2 | group5 | group14);
}
The key can be one of the following:
—Specifies that IKE use the 768-bit Diffie-Hellman prime modulus group when
group1
performing the new Diffie-Hellman exchange.
group2
—Specifies that IKE use the 1024-bit Diffie-Hellman prime modulus group when
performing the new Diffie-Hellman exchange.
—Specifies that IKE use the 1536-bit Diffie-Hellman prime modulus group when
group5
performing the new Diffie-Hellman exchange.
group14
—Specifies that IKE use the 2048-bit Diffie-Hellman prime modulus group
when performing the new Diffie-Hellman exchange.
The higher numbered groups provide more security than the lowered numbered groups,,
but require more processing time.
The IPsec policy includes a list of one or more proposals associated with an IPsec policy.
To configure the proposals in an IPsec policy, include the
one or more proposal names at the
hierarchy level:
statement and specify a
perfect-forward-secrecy
[edit services ipsec-vpn ipsec policy policy-name]
[edit services ipsec-vpn ipsec policy policy-name]
Chapter 33: Configuring IPsec
description
hierarchy level:
hierarchy
statement and specify
proposals
1103

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Acx5048Acx5096Acx500Acx1100Acx2000Acx2100 ... Show all

Table of Contents