Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Navigation  Back up to About Overview 
ContentIndex
  
[+] Expand All
[-] Collapse All

No index entries found.

advpn

Syntax

advpn {suggester {disable;}partner {connection-limit <number>;idle-threshold <packets/sec>;idle-time <seconds>;disable;}}

Hierarchy Level

[edit security ike gateway gateway-name]

Release Information

Statement introduced in Junos OS Release 12.3X48-D10. The range for the idle-threshold option and the range and default value for the idle-time option revised in Junos OS Release 12.3X48-D20.

Description

Enable Auto Discovery VPN (ADVPN) protocol on the specified gateway.

Options

suggester

VPN peer that can initiate a shortcut exchange to allow shortcut partners to establish dynamic security associations (SAs) with each other. Specify disable to disable this role on the gateway.

Note: Both suggester and partner roles are enabled if advpn is configured without explicitly configuring suggester or partner keywords. We do not support suggester and partner roles on the same gateway. You must explicitly configure disable with the suggester or partner keyword to disable that particular role. You cannot disable both suggester and partner roles on the same gateway.

partner

VPN peer that can receive a shortcut exchange suggesting that it should establish dynamic SAs with another peer. Specify disable to disable this role on the gateway.

The following options can be configured for the partner role:

connection-limit

Maximum number of shortcut tunnels that can be created with different shortcut partners using a particular gateway. The maximum number, which is also the default, is platform-dependent.

Note: Reducing the configured connection-limit value causes all active shortcut tunnels to be brought down. For example, if connection-limit is configured as 100 and you later reconfigure the number to 80, all active shortcut tunnels are brought down. Increasing the configured connection-limit value does not cause shortcut tunnels to go down.

idle-threshold

Rate, in packets per second, below which the shortcut is brought down.

Range: 3 through 5,000 packets per second.

Default: 5 packets per second.

idle-time

Duration, in seconds, after which the shortcut is deleted if the traffic remains below the idle-threshold value.

Range: 60 through 86,400 seconds.

Default: 300 seconds.

Required Privilege Level

security—To view this statement in the configuration.

security-control—To add this statement to the configuration.

Related Documentation

Modified: 2016-05-01