Juniper JUNOSE 11.0.X IP SERVICES Configuration Manual page 183

For e series broadband services routers - ip services configuration
Table of Contents

Advertisement

authentication
encryption
group
Use the requested keyword to request aggressive mode when negotiating with
peers
Use the required keyword to only request and accept aggressive mode when
negotiating with peers.
Example
host1(config-ike-policy)#aggressive-mode accepted
Use the no version to set the negotiation mode to main mode.
See aggressive-mode.
Use to specify the authentication method the router uses in the IKE policy:
preshared keys or RSA signature.
Example
host1(config-ike-policy)#authentication pre-share
Use the no version to restore the default, preshared keys.
See authentication.
Use to specify one of the following encryption algorithms to use in the IKE policy:
3des 168-bit 3DES-CBC
des 56-bit DES-CBC
Example
host1(config-ike-policy)#encryption 3des
Use the no version to restore the default encryption algorithm, 3DES.
See encryption.
Use to assign a Diffie-Hellman group to the IKE policy. Specify:
1 768-bit group
2 1024-bit group
5 1536-bit group
Example
host1(config-ike-policy)#group 5
Use the no version to restore the default.
See group.
Chapter 5: Configuring IPSec
157
Configuration Tasks

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.0.x

Table of Contents