Feature Explorer AI AI

×

Subscribe now to get the Latest Updates

Watch a 2-minute overview video

Configuring forwarding class on IPsec VPNs

More Information:

Configuring forwarding class on IPsec VPNs

The forwarding classes configured on device can be mapped to IPsec security associations (SAs). Multiple IPsec SAs are negotiated on the same IKE SA with a peer device, one SA per forwarding class configured in IPsec. A unique IPsec SA is negotiated with the VPN peer for each forwarding class. By mapping the forwarding class to the IPsec SA, all the packets with a certain class-of-service (CoS) value will get quality-of-service (QoS) treatment between the peer devices thus avoiding packet drop due to the anti-replay window. This feature provides QoS for IPsec when peer devices allow for multiple SA negotiation.
Product / Application Software Introduced Release
vSRX Junos OS 18.2R1
SRX300 Junos OS 18.2R1
SRX320 Junos OS 18.2R1
SRX340 Junos OS 18.2R1
SRX345 Junos OS 18.2R1
SRX380 Junos OS 20.1R1
SRX550 HM Junos OS 18.2R1
SRX1500 Junos OS 18.2R1
SRX1600 Junos OS 23.4R1
SRX2300 Junos OS 23.4R1
SRX4100 Junos OS 18.2R1
SRX4120 Junos OS 25.2R1
SRX4200 Junos OS 18.2R1
SRX4300 Junos OS 24.2R1
SRX4600 Junos OS 18.2R1
SRX4700 Junos OS 24.4R1-S2
SRX5400 Junos OS 18.2R1
SRX5600 Junos OS 18.2R1
SRX5800 Junos OS 18.2R1