[Contents] [Prev] [Next] [Index] [Report an Error]

security-association

See the following sections:

security-association (JUNOS Software)

Syntax

security-association sa-name {
dynamic {
ipsec-policy policy-name;
replay-window-size (32 | 64);
}
manual {
direction (JUNOS Software) (inbound | outbound | bi-directional) {
authentication {
algorithm (hmac-md5-96 | hmac-sha1-96);
key (ascii-text key | hexadecimal key);
}
auxiliary-spi auxiliary-spi-value;
encryption {
algorithm (des-cbc | 3des-cbc);
key (ascii-text key | hexadecimal key);
}
protocol ( ah | esp | bundle);
spi spi-value;
}
mode (tunnel | transport);
}
}

Hierarchy Level

[edit security ipsec]

Release Information

Statement introduced before JUNOS Release 7.4.

Description

Configure an IPSec security association.

Options

name—Name of the security association.

The remaining statements are explained separately.

Usage Guidelines

See Configuring Security Associations.

Required Privilege Level

system—To view this statement in the configuration.

system-control—To add this statement to the configuration.

security-association (JUNOS-FIPS Software)

Syntax

security-association {
manual {
direction (bidirectional | inbound | outbound) {
protocol esp;
spi spi-value;
encryption {
algorithm 3des-cbc;
key ascii-text ascii-text-string;
}
}
}
}

Hierarchy Level

[edit security ipsec internal]

Release Information

Statement introduced before JUNOS Release 7.4.

Description

Define a security association (SA) for internal Routing-Engine-to-Routing-Engine communication.

Options

The remaining statements are explained separately.

Usage Guidelines

See Configuring Internal IPSec for JUNOS-FIPS.

Required Privilege Level

Crypto Officer—To view and add this statement in the configuration.

Related Topics

Secure Configuration Guide for Common Criteria and JUNOS-FIPS


[Contents] [Prev] [Next] [Index] [Report an Error]