multi-sa
Syntax
multi-sa { forwarding-class expedited-forwarding | assured-forwarding | best-effort | network-control; }
Hierarchy Level
[edit security ipsec vpn]
Description
Negotiate multiple security association (SAs) based on configuration choice. Multiple SAs negotiates with the same traffic selector on the same IKE SA. By negotiating multiple SAs, the peer gateways have more replay windows. If the peer gateways create separate multiple SAs for the configured Forwarding-Classes (FC), then potentially a separate anti-replay window is available for each FC value. With this mapping, even if CoS can reorder packets, reordering is done with in a given multiple SA, thus avoiding packets drop due to the anti-replay checks.
Options
forwarding-class | Forwarding classes (FCs) allow you to group packets for transmission and to assign packets to output queues.
|
Required Privilege Level
security
Release Information
Statement introduced in Junos OS Release 18.2R1.