An IP Security (IPSec) tunnel allows access to a private network through a secure tunnel. This feature is particularly useful when a private network is divided among multiple sites, and transit between the sites must occur on a public network. To ensure secure transport of packets across the public network to the multiple sites, individual tunnels are configured. Network Address Translation (NAT) enables packets outbound through a tunnel to be filtered by source address.
Digital certificates are an optional way to authenticate data transmitted through an IPSec tunnel by using a third-party certificate authority (CA) to verify the identity of each device on either end of the tunnel.
![]() |
You must have a license to configure an IPSec tunnel. For license details, see the J-series Services Router Administration Guide. |
This chapter contains the following topics. For more information about IPSec, NAT and digital certificates, see the JUNOS System Basics Configuration Guide and the JUNOS Services Interfaces Configuration Guide.