VPNs
-
Multiple certificate types support on IKEv2 (MX240, MX480, and MX960 in USF mode, SRX1500, SRX4100, SRX4200, SRX4600, SRX5400, SRX5600, SRX5800, and vSRX3.0 running IKED process)—Starting in Junos OS Release 22.4R1, you can establish the IKEv2 and IPsec SA tunnels irrespective of the type of certificate used on an initiator and a responder.
To support the multiple certificate types, configure the authentication method as certificates using the
certificates
option at the[security ike proposal proposal-name authentication-method]
hierarchy.[See proposal (Security IKE).]