Changes between Version 4 and Version 5 of HowtoJuniperSsg
- Timestamp:
- 04/05/09 17:19:53 (17 months ago)
Legend:
- Unmodified
- Added
- Removed
- Modified
-
HowtoJuniperSsg
v4 v5 20 20 Create a user that is used to define the phase1 id parameters. Navigate to the following screen using the tree pane on the left hand side of the browser interface. 21 21 22 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/nav-1.jpg)]]22 [[Image(http://www.shrew.net/static/howto/JuniperSsg/nav-1.jpg)]] 23 23 24 24 Click the New button and define the following parameters. … … 31 31 * IKE Identity = client.domain.com 32 32 33 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-1.jpg)]]33 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-1.jpg)]] 34 34 35 35 === Create a Local Key Group === … … 37 37 Create a Local Group that can be assigned to an Auto Key Advanced Gateway. Navigate to the following screen using the tree pane on the left hand side of the browser interface. 38 38 39 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/nav-2.jpg)]]39 [[Image(http://www.shrew.net/static/howto/JuniperSsg/nav-2.jpg)]] 40 40 41 41 Click the New button and define the group name as vpnclient_group. Also add the vpnclient_ph1id user object as a group member. 42 42 43 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-2.jpg)]]43 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-2.jpg)]] 44 44 45 45 === Create an Auto Key Advanced Gateway === … … 47 47 Create an auto key advanced gateway to configure the phase1 parameters. Navigate to the following screen using the tree pane on the left hand side of the browser interface. 48 48 49 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/nav-3.jpg)]]49 [[Image(http://www.shrew.net/static/howto/JuniperSsg/nav-3.jpg)]] 50 50 51 51 Click the New button and define the following parameters. … … 58 58 * Local ID = vpngw.domain.com 59 59 60 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-3a.jpg)]]60 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-3a.jpg)]] 61 61 62 62 ==== Define Advanced Parameters ==== … … 79 79 When finished click Return. 80 80 81 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-3b.jpg)]]81 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-3b.jpg)]] 82 82 83 83 ==== Define Xauth Parameters ==== … … 85 85 You will now see your auto key advanced gateway listed. Click non the Xauth button in the Configure column. 86 86 87 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/nav-4.jpg)]]87 [[Image(http://www.shrew.net/static/howto/JuniperSsg/nav-4.jpg)]] 88 88 89 89 Define the following parameters. … … 96 96 When finished click OK. 97 97 98 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-4.jpg)]]98 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-4.jpg)]] 99 99 100 100 === Create an Auto Key IKE Gateway === … … 102 102 Create an auto key IKE gateway to configure the phase2 parameters. Navigate to the following screen using the tree pane on the left hand side of the browser interface. 103 103 104 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/nav-5.jpg)]]104 [[Image(http://www.shrew.net/static/howto/JuniperSsg/nav-5.jpg)]] 105 105 106 106 Clicking the New button and define the following parameters. … … 110 110 * Remote Gateway Predefined = vpnclient_gateway 111 111 112 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-5a.jpg)]]112 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-5a.jpg)]] 113 113 114 114 ==== Define Advanced Parameters ==== … … 125 125 When finished click Return. 126 126 127 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-5b.jpg)]]127 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-5b.jpg)]] 128 128 129 129 == Create a Client Address Pool == … … 131 131 Create a pool of addresses to be assigned to VPN clients. Navigate to the following screen using the tree pane on the left hand side of the browser interface. 132 132 133 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/nav-6.jpg)]]133 [[Image(http://www.shrew.net/static/howto/JuniperSsg/nav-6.jpg)]] 134 134 135 135 Clicking the New button and define an IP Pool. For example, you could define a pool 136 136 named vpnclient with a start IP address of 10.2.21.1 and and end address of 10.2.21.254. 137 137 138 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-6.jpg)]]138 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-6.jpg)]] 139 139 140 140 == Set Client Configuration Parameters == … … 143 143 parameters. Navigate to the following screen using the tree pane on the left hand side of the browser interface. 144 144 145 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/nav-7.jpg)]]145 [[Image(http://www.shrew.net/static/howto/JuniperSsg/nav-7.jpg)]] 146 146 147 147 Define the following parameters. … … 157 157 * WINS Secondary Server IP = [ private WINS secondary address ] 158 158 159 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-7.jpg)]]159 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-7.jpg)]] 160 160 161 161 == Configure IPsec Policies == … … 163 163 The last step for the tunnel configuration is to define policies that allow protected traffic to pass into your private network from the client. Navigate to the following screen using the tree pane on the left hand side of the browser interface. 164 164 165 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/nav-8.jpg)]]165 [[Image(http://www.shrew.net/static/howto/JuniperSsg/nav-8.jpg)]] 166 166 167 167 To create a new IPsec Policy, the from and to zones must be specified. An IPsec VPN Client policy is defined. Select the following zones and click the New button. … … 170 170 * To = Trust 171 171 172 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-8a.jpg)]]172 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-8a.jpg)]] 173 173 174 174 Define the following parameters. … … 184 184 * Tunnel = vpnclient_tunnel [ Auto Key IKE vpn name ] 185 185 186 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-8b.jpg)]]186 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-8b.jpg)]] 187 187 188 188 == Create Local User Accounts == … … 190 190 Create local user accounts that will be used during Xauth. Navigate to the following screen using the tree pane on the left hand side of the browser interface. 191 191 192 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/nav-1.jpg)]]192 [[Image(http://www.shrew.net/static/howto/JuniperSsg/nav-1.jpg)]] 193 193 194 194 Click the new button and define the following parameters. … … 202 202 When finished press OK. 203 203 204 [[Image(http://www.shrew.net/ vpn/howto/JuniperSsg/ssg-9.jpg)]]204 [[Image(http://www.shrew.net/static/howto/JuniperSsg/ssg-9.jpg)]] 205 205 206 206 == Client Configuration == … … 242 242 == Resources == 243 243 244 * [http://www.shrew.net/ vpn/howto/JuniperSsg/juniperssg.vpn Example Client configuration]244 * [http://www.shrew.net/static/howto/JuniperSsg/juniperssg.vpn Example Client configuration]