Configuring Match Conditions In Ipsec Rules; Configuring Actions In Ipsec Rules; Configuring Destination Address - Juniper ACX1000 Configuration Manual

Junos os; acx series universal access router
Hide thumbs Also See for ACX1000:
Table of Contents

Advertisement

Configuring Match Conditions in IPsec Rules

Configuring Actions in IPsec Rules

Configuring Destination Address

Copyright © 2017, Juniper Networks, Inc.
To configure the match conditions in an IPsec rule, include the
[edit services ipsec-vpn rule rule-name term term-name]
[edit services ipsec-vpn rule rule-name term term-name]
from {
destination-address address;
source-address address;
}
You can use either the source address or the destination address as a match condition,
in the same way that you would configure a firewall filter; for more information, see the
Routing Policies, Firewall Filters, and Traffic Policers Feature Guide.
IPsec services on ACX Series support IPv4 address formats. If you do not specifically
configure either the source address or destination address, the default value
(IPv4 ANY) is used.
To configure actions in an IPsec rule, include the
ipsec-vpn rule rule-name term term-name]
[edit services ipsec-vpn rule rule-name term term-name]
then {
dynamic {
ike-policy policy-name;
ipsec-policy policy-name;
}
remote-gateway address;
}
The principal IPsec actions are to configure a dynamic or manual SA:
You configure a dynamic SA by including the
ipsec-vpn rule rule-name term term-name then]
you have configured at the
ike]
hierarchy levels; for more information, see Configuring Dynamic Security Associations.
You configure a manual SA by including the
ipsec-vpn rule rule-name term term-name then]
see Configuring Manual Security Associations.
To specify the remote address to which the IPsec traffic is directed, include the
statement at the
remote-gateway
hierarchy level:
then]
[edit services ipsec-vpn rule rule-name term term-name then]
remote-gateway address;
statement at the
then
hierarchy level:
dynamic
hierarchy level and referencing policies
[edit services ipsec-vpn ipsec]
statement at the
manual
hierarchy level; for more information,
[edit services ipsec-vpn rule rule-name term term-name
Chapter 33: Configuring IPsec
from
statement at the
hierarchy level:
0.0.0.0/0
[edit services
statement at the
[edit services
and
[edit services ipsec-vpn
[edit services
1107

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Acx5048Acx5096Acx500Acx1100Acx2000Acx2100 ... Show all

Table of Contents