Juniper JUNOSE 11.2.X IP SERVICES Configuration Manual page 316

For e series broadband services routers - ip services configuration
Table of Contents

Advertisement

JunosE 11.2.x IP Services Configuration Guide
application
290
host1(config-ipsec-transport-profile)#
Specify one or more types of application that the profile secures.
2.
host1(config-ipsec-transport-profile)#application gre dvmrp l2tp
You can then set any of the following parameters for the profile:
Set a lifetime range for the IPSec connection in volume of traffic or seconds.
host1(config-ipsec-transport-profile)#lifetime seconds 3600 28800 kilobytes 102400
4294967295
Configure Perfect Forward Secrecy (PFS) for connections created with this IPSec
transport profile.
host1(config-ipsec-transport-profile)#pfs group 5
Specify one or more transform sets that an IPSec transport connection uses to negotiate
a transform algorithm.
host1(config-ipsec-transport-profile)#transform-set esp-3des-hmac-sha
esp-3des-hmac-md5
To display the available transform sets, issue the transform-set ? command.
Specify the local endpoint (for L2TP, the LNS address) of the IPSec transport
connection, and enter Local IPSec Transport Profile mode.
host1(config-ipsec-transport-profile)#local ip address 10.10.1.1
host1(config-ipsec-transport-profile-local)#
(Optional) Configure a key for IKE negotiations. For example:
Enter the unencrypted key. The router encrypts the key and stores it in encrypted form.
You can no longer retrieve the unencrypted key.
host1(config-ipsec-transport-profile-local)#pre-share secretforGre
Use to specify the types of application secured by connections created with this IPSec
transport profile. You can specify multiple applications on the same command line:
dvmrp—Secures DVMRP tunnel traffic
gre—Secures GRE tunnel traffic
l2tp—Secures L2TP traffic
l2tp-nat-passthrough—Secures L2TP traffic and also allows clients to connect from
behind NAT devices that support IPSec passthrough. To allow these clients to
connect, the router:
Does not generate or verify UDP checksums. This does not compromise security,
because IPSec protects UDP packets with an authentication algorithm far stronger
than UDP checksums.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.2.x

Table of Contents