Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

header-navigation
keyboard_arrow_up
close
keyboard_arrow_left
Junos CLI Reference
Table of Contents Expand all
list Table of Contents
file_download PDF
{ "lLangCode": "en", "lName": "English", "lCountryCode": "us", "transcode": "en_US" }
English
keyboard_arrow_right

security-association (Junos-FIPS Software)

date_range 20-Nov-23

Syntax

content_copy zoom_out_map
security-association sa-name {
    dynamic {
        ipsec-policy policy-name;
        replay-window-size (32 | 64); 
    }
    manual {
        direction (inbound | outbound | bi-directional) {
            authentication {
                algorithm (hmac-sha1-96 | hmac-sha2-256); 
                key (ascii-text key | hexadecimal key); 
            }
            auxiliary-spi auxiliary-spi-value;
            encryption {
                algorithm 3des-cbc; 
                key (ascii-text key | hexadecimal key); 
            }
            protocol ( ah | esp | bundle);
            spi spi-value; 
        }
        mode (tunnel | transport);
    }
}

Hierarchy Level

content_copy zoom_out_map
[edit security ipsec]

Description

Configure an IPsec security association.

Options

sa-name—Name of the security association.

The remaining statements are explained separately. See CLI Explorer.

Required Privilege Level

Crypto Officer—To view and add this statement in the configuration.

Release Information

Statement introduced before Junos OS Release 7.4.

Note:

We recommend that you configure the IPsec keys as hexadecimal keys for maximum key strength with Junos OS in FIPS mode.

footer-navigation