Security Services Configuration Guidelines
To configure security services, include the following statements at the
[edit security]hierarchy level:[edit security]certificates {cache-sizebytes;cache-timeout-negativeseconds;certification-authorityca-profile-name{ca-nameca-identity;encoding (binary | pem);crlfile-name;filecertificate-file-name;enrollment-urlurl-name;ldap-urlurl-name;}enrollment-retry number;localcertificate-name;maximum-certificatesnumber;path-lengthbytes;}ike {proposalike-proposal-name{authentication-algorithm (md5 | sha1);authentication-method (dsa-signatures | pre-shared-keys | rsa-signatures);dh-group (group1 | group2);encryption-algorithm (3des-cbc | des-cbc);lifetime-secondsseconds;}policyike-peer-address{descriptionpolicy-description;encoding (binary | pem);identityidentity-name;local-certificatecertificate-file-name;local-key-pairprivate-public-key-file;mode (aggressive | main);pre-shared-key (ascii-textkey| hexadecimalkey);proposal[ike-proposal-names];}ipsec {proposalipsec-proposal-name{authentication-algorithm (hmac-md5-96 | hmac-sha1-96);encryption-algorithm (3des-cbc | des-cbc);lifetime-secondsseconds;protocol (ah | esp | bundle);}policyipsec-policy-name{perfect-forward-secrecy {keys (group1 | group2);}proposal [ipsec-proposal-names];}security-associationname{ mode (tunnel | transport);manual {direction (inbound | outbound | bi-directional) {auxiliary-spi auxiliary-spi;spispi-value;protocol (ah | esp | bundle);authentication {algorithm (hmac-md5-96 | hmac-sha1-96);key (ascii-textkey| hexadecimalkey);}encryption {algorithm (des-cbc | 3des-cbc);key (ascii-textkey| hexadecimalkey);}}dynamic {replay-window-size (32 | 64);ipsec-policypolicy-name;}traceoptions {filefilename<filesnumber> < sizesize>;flag all;flag database;flag general;flag ike;flag parse;flag policy-manager;flag routing-socket;flag timer;}}This chapter describes the following tasks for configuring Internet Protocol Security (IPSec) and the Internet Key Exchange (IKE):
- Minimum Manual SA Configuration
- Minimum IKE Configuration
- Minimum Digital Certificates Configuration for IKE
- Configure Security Associations
- Configure an IKE Proposal (Dynamic SAs Only)
- Configure an IKE Policy for Preshared Keys
- Configure an IPSec Proposal
- Configure the IPSec Policy
- Digital Certificates Guidelines
- Configure Trace Options
- Configure the ES PIC
- Configure Traffic
- Configure an ES Tunnel Interface for a Layer 3 VPN
- JUNOScript XNM-SSL Service