Packets; Using Ipsec To Secure Ospfv3 Networks (Cli Procedure); Configuring Security Associations - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

Complete Software Guide for Junos
Disabling or Enabling Distributed Periodic Packet Management for LACP Packets
Related
Documentation

Using IPsec to Secure OSPFv3 Networks (CLI Procedure)

Configuring Security Associations

1930
®
OS for EX Series Ethernet Switches, Release 10.4
user@switch# delete ppm no-delegate-processing
Distributed PPM is enabled by default. Disable distributed PPM for only LACP packets if
you need to move all PPM processing for LACP packets to the Routing Engine.
To disable distributed PPM for LACP packets:
[edit protocols]
user@switch# set lacp ppm centralized
To enable distributed PPM for LACP packets if it was previously disabled:
[edit protocols]
user@switch# delete lacp ppm centralized
Understanding Distributed Periodic Packet Management on EX Series Switches on
page 1904
Understanding Aggregated Ethernet Interfaces and LACP on page 1244
OSPF version 3 (OSPFv3) does not have a built-in authentication method and relies on
IP Security (IPsec) to provide this functionality. You can use IPsec to secure OSPFv3
interfaces on EX Series switches.
This topic includes:
Configuring Security Associations on page 1930
Securing OPSFv3 Networks on page 1931
When you configure a security association (SA), include your choices for authentication,
encryption, direction, mode, protocol, and security parameter index (SPI).
To configure a security association:
Specify a name for the security association:
1.
[edit security ipsec]
user@switch# set security-association sa-name
Specify the mode of the security association:
2.
[edit security ipsec security-association sa-name]
user@switch# set mode transport
Specify the type of security association:
3.
[edit security ipsec security-association sa-name]
user@switch# set type manual
Specify the direction of the security association:
4.
[edit security ipsec security-association sa-name]
user@switch# set direction bidirectional
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents