Configuring Ipsec Transport Profiles - Juniper JUNOSE 11.0.X IP SERVICES Configuration Manual

For e series broadband services routers - ip services configuration
Table of Contents

Advertisement

JUNOSe 11.0.x IP Services Configuration Guide
interface tunnel gre
NOTE: After you create a clear GRE or DVMRP tunnel, you cannot convert it to an
IPSec-secured tunnel, or vice versa. You must delete the tunnel configuration, then
reconfigure the tunnel as the new type.

Configuring IPSec Transport Profiles

To configure an IPSec transport profile that will be used to secure DVMRP, GRE, or
L2TP tunnels:
1.
2.
You can then set any of the following parameters for the profile:
302
Configuring IPSec Transport Profiles
Use with the ipsec-transport keyword to create a GRE or DVMRP tunnel that is
protected with IPSec in transport mode.
You can establish the tunnel on a virtual router other than the current virtual
router.
Example
host1(config)#interface tunnel gre:denver-tunnel-5 transport-virtual-router denver
ipsec-transport
host1(config-if)#
Use the no version to remove the tunnel.
See interface tunnel.
Create the profile.
host1(config)#ipsec transport profile secureGre virtual-router default ip address
5.5.5.5
host1(config-ipsec-transport-profile)#
Specify one or more types of application that the profile secures.
host1(config-ipsec-transport-profile)#application gre dvmrp l2tp
Set a lifetime range for the IPSec connection in volume of traffic or seconds.
host1(config-ipsec-transport-profile)#lifetime seconds 3600 28800 kilobytes
102400 4294967295
Configure Perfect Forward Secrecy (PFS) for connections created with this IPSec
transport profile.
host1(config-ipsec-transport-profile)#pfs group 5
Specify one or more transform sets that an IPSec transport connection uses to
negotiate a transform algorithm.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.0.x

Table of Contents