Juniper JUNOSE SOFTWARE FOR E SERIES 11.3.X - IP SERVICES CONFIGURATION GUIDE 2010-10-01 Configuration Manual page 318

Software for e series broadband services routers ip services configuration guide
Table of Contents

Advertisement

JunosE 11.3.x IP Services Configuration Guide
pfs group
pre-share
292
Use to specify the local endpoint (for L2TP, the LNS address) of the IPSec transport
connection and to enter Local IPSec Transport Profile Configuration mode.
You can enter this command multiple times in an IPSec transport profile.
You can enter a fixed IP address or the wildcard address, 0.0.0.0. The wildcard address
has a lower precedence than a fixed IP address.
CAUTION: We recommend that you do not use address 0.0.0.0, because
it allows any address to accept IKE calls, and it creates a group preshared
key, which is not fully secure.
Example
host1(config-ipsec-transport-profile)#local ip address 192.168.1.2
host1(config-ipsec-transport-profile-local)#
Use the no version to delete the IP address.
See local ip address.
Use to configure perfect forward secrecy for connections created with this IPSec
transport profile.
Assign a Diffie-Hellman prime modulus group using one of the following keywords:
1—768-bit group
2—1024-bit group
5—1536-bit group
Example
host1(config-ipsec-transport-profile)#pfs group 5
Use the no version to remove PFS from this profile, which is the default setting.
See pfs group.
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.3

Table of Contents