Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Junos CLI Reference
Table of Contents Expand all
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

security-association (Junos OS)

date_range 20-Nov-23

Syntax

content_copy zoom_out_map
security-association sa-name {
    dynamic {
        ipsec-policy policy-name;
        replay-window-size (32 | 64); 
    }
    manual {
        direction (inbound | outbound | bi-directional) {
            authentication {
                algorithm (hmac-sha1-96 | hmac-sha2-256); 
                key (ascii-text key | hexadecimal key); 
            }
            auxiliary-spi auxiliary-spi-value;
            encryption {
                algorithm (des-cbc | 3des-cbc); 
                key (ascii-text key | hexadecimal key); 
            }
            protocol ( ah | esp | bundle);
            spi spi-value; 
        }
        mode (tunnel | transport);
    }
}

Hierarchy Level

content_copy zoom_out_map
[edit security ipsec]

Description

Configure an IPsec security association.

Options

sa-name—Name of the security association.

The remaining statements are explained separately. See CLI Explorer.

Required Privilege Level

system—To view this statement in the configuration.

system-control—To add this statement to the configuration.

Release Information

Statement introduced before Junos OS Release 7.4.

Note:

You must configure the IPsec keys as hexadecimal keys for maximum key strength with Junos OS in FIPS mode.

footer-navigation