See the following sections:
- protocol (ah | esp | bundle);
- [edit security ipsec proposal ipsec-proposal-name],
- [edit security ipsec security-association sa-name manual direction (inbound | outbound | bidirectional)]
Statement introduced before JUNOS Release 7.4.
Define the IPSec protocol for a manual or dynamic SA.
ah—Authentication Header protocol
bundle—AH and ESP protocols
esp—ESP protocol (the tunnel statement must be included at the [edit security ipsec security-association sa-name mode hierarchy level)
See Configuring the Protocol for a Manual SA and Configuring the Protocol for a Dynamic IPSec SA.
admin—To view this statement in the configuration.
admin-control—To add this statement to the configuration.
- protocol esp;
- [edit security ipsec internal security-association manual
direction]
Statement introduced before JUNOS Release 7.4.
The protocol used for the internal Routing-Engine-to-Routing-Engine IPSec security association (SA) configuration.
Only esp is supported.
See Configuring Internal IPSec for JUNOS-FIPS.
Crypto Officer—To add and view this statement in the configuration.
Secure Configuration Guide for Common Criteria and JUNOS-FIPS