Checking Your Work
To verify proper operation of a dynamic endpoint tunnel configured on the AS PIC, use the following command:
show services ipsec-vpn ipsec security-associations (detail)The following section shows output from this command used with the configuration example. The dynamically created rule
_junos_appears in the output, as well as the establishment of the inbound and outbound dynamically created tunnels.user@router>show services ipsec-vpn ipsec security-associations detailService set: dynamic_nh_ssRule:_junos_, Term: tunnel4, Tunnel index: 4Local gateway: 10.7.7.2, Remote gateway: 10.7.7.1Local identity: ipv4(any:0,[0..3]=10.255.14.63)Remote identity: ipv4(any:0,[0..3]=10.255.14.64)Direction: inbound, SPI: 428111023, AUX-SPI: 0Mode: tunnel, Type: dynamic, State: InstalledProtocol: ESP, Authentication: hmac-sha1-96, Encryption: 3des-cbcSoft lifetime: Expires in 27660 secondsHard lifetime: Expires in 27750 secondsAnti-replay service: Enabled, Replay window size: 64Direction: outbound, SPI: 4035429231, AUX-SPI: 0Mode: tunnel, Type: dynamic, State: InstalledProtocol: ESP, Authentication: hmac-sha1-96, Encryption: 3des-cbcSoft lifetime: Expires in 27660 secondsHard lifetime: Expires in 27750 secondsAnti-replay service: Enabled, Replay window size: 64