[j-nsp] Configuring ipsec with an Adaptive Services PIC

John Holmes jwholmes at earthlink.net
Wed May 25 12:57:47 EDT 2005


John Holmes wrote:

>  I have read the information and tried to configure using the AS PIC 
>IKE Dynamic SA Configuration. What I ended up with worked but only for 
>the specific networks in the source-address and destination-address 
>list. For example, I have
>
>10.10.10.0/26
>                         ---------------Router 
>A------10.5.5.0/29--------Router B--------- 10.1.1.0/22
>10.10.10.64/26
>
>
>
>  
>
Let me try this again:


Router A has 10.10.10.0/26 and 10.10.10.64/26 behind it

Router B has 10.1.1.0/22 behind it

How can I have both Router A networks use the tunnel to Router B? JunOS 
will only allow me to put a single network into the source/destination 
spots. Will an aggregate route advertised from Router A allow me to 
change my rule-ike addresses to include both subnets and direct the 
networks into the tunnel?



More information about the juniper-nsp mailing list