Security Services Configuration Guidelines
To configure security services, include the following statements at the
[edit security]hierarchy level:[edit security]certificates {cache-sizebytes;cache-timeout-negativeseconds;certification-authorityca-profile-name{ca-nameca-identity;crlfile-name;encoding (binary | pem);enrollment-urlurl-name;filecertificate-filename;ldap-urlurl-name;}enrollment-retryattempts;localcertificate-filename{certificate-key-string;load-key-filekey-filename;}maximum-certificatesnumber;path-lengthcertificate-path-length;}ike {proposalike-proposal-name{authentication-algorithm (md5 | sha1);authentication-method (dsa-signatures | pre-shared-keys | rsa-signatures);descriptiondescription;dh-group (group1 | group2);encryption-algorithm (3des-cbc | des-cbc);lifetime-secondsseconds;}policyike-peer-address{descriptiondescription;encoding (binary | pem);identityidentity-name;local-certificatecertificate-filename;local-key-pairprivate-public-key-file;mode (aggressive | main);pre-shared-key (ascii-textkey| hexadecimalkey);proposals[proposal-names];}}ipsec {proposalipsec-proposal-name{authentication-algorithm (hmac-md5-96 | hmac-sha1-96);descriptiondescription;encryption-algorithm (3des-cbc | des-cbc);lifetime-secondsseconds;protocol (ah | esp | bundle);}policyipsec-policy-name{descriptiondescription;perfect-forward-secrecy {keys (group1 | group2);}proposals [proposal-names];}security-associationsa-name{descriptiondescription;dynamic {ipsec-policypolicy-name;replay-window-size (32 | 64);}manual {direction (inbound | outbound | bi-directional) {authentication {algorithm (hmac-md5-96 | hmac-sha1-96);key (ascii-textkey| hexadecimalkey);}auxiliary-spi auxiliary-spi;encryption {algorithm (des-cbc | 3des-cbc);key (ascii-textkey| hexadecimalkey);}protocol (ah | esp | bundle);spispi-value;}}mode (tunnel | transport);}}traceoptions {filefilename<filesnumber> < sizesize>;flag all;flag database;flag general;flag ike;flag parse;flag policy-manager;flag routing-socket;flag timer;}This chapter describes the following tasks for configuring IPSec and Internet Key Exchange (IKE):
- Minimum Manual SA Configuration
- Minimum IKE Configuration
- Minimum Digital Certificates Configuration for IKE
- Configuring Security Associations
- Configuring an IKE Proposal (Dynamic SAs Only)
- Configuring an IKE Policy for Preshared Keys
- Configuring an IPSec Proposal
- Configuring the IPSec Policy
- Configuring Digital Certificates
- Configuring Trace Options
- Configuring the ES PIC
- Configuring Traffic
- Configuring an ES Tunnel Interface for a Layer 3 VPN
- Using JUNOScript SSL Service