Appending A Domain Suffix To A Username; Overriding Ipsec Local And Peer Identities For Sa Negotiations - Juniper JUNOSE 11.0.X IP SERVICES Configuration Manual

For e series broadband services routers - ip services configuration
Table of Contents

Advertisement

JUNOSe 11.0.x IP Services Configuration Guide

Appending a Domain Suffix to a Username

The VPN to which a user is to be terminated is sometimes known from the IKE
identities attached to the user. However, to assist in connecting users to the correct
AAA domain for authentication, you can use the domain-suffix command to append
a domain suffix to the username. Using the default, no domain suffix, passes
usernames transparently to AAA.
domain-suffix

Overriding IPSec Local and Peer Identities for SA Negotiations

You can use the local ip identity and peer ip identity commands to override the
local and peer identities used for SA negotiations (respectively).
local ip identity
peer ip identity
184
Configuring IPSec Tunnel Profiles
See ike peer-identity domain-name.
See ike peer-identity ip address.
See ike peer-identity username.
Use to specify a domain suffix that you want to append to any usernames
received on this profile.
Example
host1(config-ipsec-tunnel-profile)#domain-suffix domain2
Use the no version to restore the default value, no domain suffix, and usernames
are passed transparently to AAA.
See domain-suffix.
Use to override the local identity (phase 2 identity) used for IPSec security
association negotiations. For IPSec negotiations to succeed, the local and peer
identities at one end of the tunnel must match the peer and local identities at
the other end (respectively).
Example
host1(config-ipsec-tunnel-profile)#local ip identity range 10.30.11.1 10.30.11.50
Use the no version to restore the default value, the internal IP address allocated
for the subscriber.
See local ip identity.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.0.x

Table of Contents