}
}
ipsec {
proposal ipsec-proposal-name {
protocol {
ah;
esp;
}
authentication-algorithm {
hmac-md5-96;
hmac-sha-256-128;
hmac-sha1-96;
}
encryption-algorithm {
3des-cbc;
aes-128-cbc;
aes-192-cbc;
aes-256-cbc;
des-cbc;
}
lifetime-seconds lifetime-in-seconds;
}
policy ipsec-policy-name {
perfect-forward-secrecy {
keys {
group1;
group14;
group2;
group5;
}
}
proposals proposal-name;
}
vpn vpn-name {
ike {
gateway remote-gateway-name;
ipsec-policy ipsec-policy-name;
}
traffic-selector {
traffic-selector-name1 {
local-ip local-traffic-selector-ip-address;
remote-ip remote-traffic-selector-ip-address;
}
traffic-selector-name2 {
local-ip local-traffic-selector-ip-address;
remote-ip remote-traffic-selector-ip-address;
}
}
establish-tunnels immediately;
}
}
policies {
from-zone {
from-zone-name {
to-zone to--zone-name;
}
189Copyright © 2017, Juniper Networks, Inc.
Chapter 9: IPSec-NM Configuration Statements and Operational Commands