Juniper JUNOSE 11.0.X IP SERVICES Configuration Manual page 330

For e series broadband services routers - ip services configuration
Table of Contents

Advertisement

JUNOSe 11.0.x IP Services Configuration Guide
lifetime
local ip address
CAUTION: We recommend that you do not use address 0.0.0.0, because it allows
any address to accept IKE calls, and it creates a group preshared key, which is not
fully secure.
304
Configuring IPSec Transport Profiles
For L2TP/IPSec connections, you can enter a fixed IP address or the wildcard
address, 0.0.0.0. If you use the wildcard address, the profile accepts any
remote client connection, which is a typical scenario for secure remote
access.
For GRE/IPSec and DVMRP/IPSec connections, you must enter a fixed
address; the 0.0.0.0 wildcard address is not accepted and will return an
error.
Example
host1(config)#ipsec transport profile secureL2tp virtual-router default ip address
5.5.5.5
host1(config-ipsec-transport-profile)#
Use the no version to delete the profile.
See ipsec transport profile.
Use to set a lifetime range for the IPSec connection in volume of traffic or in
seconds or both.
If the PC client offers a lifetime within this range, the router accepts the offer. If
the PC client offers a lifetime outside this range, the router rejects the connection.
Example
host1(config-ipsec-transport-profile)#lifetime seconds 900 86400 kilobytes
100000 4294967295
Use the no version to restore the default values, 100000–4294967295 KB and
900–86400 seconds (0.25–24 hours).
See lifetime.
Use to specify the local endpoint (for L2TP, the LNS address) of the IPSec transport
connection and to enter Local IPSec Transport Profile Configuration mode.
You can enter this command multiple times in an IPSec transport profile.
You can enter a fixed IP address or the wildcard address, 0.0.0.0. The wildcard
address has a lower precedence than a fixed IP address.
Example
host1(config-ipsec-transport-profile)#local ip address 192.168.1.2
host1(config-ipsec-transport-profile-local)#

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.0.x

Table of Contents