Question

configuring ipsec vpn between netscreen and cisco

Asked by: shwaqar82

Hi,
I have attached the diagram. I am trying to creat ipsec vpn between the netscreen and cisco router. Can you please tell me if I can do this? Is my diagram conceptually correct?
Is ip addressing correct in my topology?

This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.

Subscribe now for full access to Experts Exchange and get

Instant Access to this Solution

  • Plus...
  • 30 Day FREE access, no risk, no obligation
  • Collaborate with the world's top tech experts
  • Unlimited access to our exclusive solution database
  • Never be left without tech help again

Subscribe Now

Asked On
2009-08-01 at 09:27:52ID24618979
Tags

ipsec vpn netscreen cisco

Topics

Virtual Private Networking (VPN)

,

IPSec Security Protocol

Participating Experts
2
Points
500
Comments
24

Trusted by hundreds of thousands everyday for fast, accurate and reliable tech support.

  • "The time we save is the biggest benefit of Experts Exchange to Warner Bros. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange." Mike Kapnisakis, Warner Bros.
  • "Our team likes having a resource that is more secure than just using Google and most experts using this service really know their stuff. It's nice to look here first versus using Google." Dayna Sellner, Lockheed Martin
  • "Anytime that I've been stumped with a problem, 9 out of 10 times Experts Exchange has either the accepted solution or an open discussion of the potential solution to the problem." Kenny Red, eBay Inc.

See what Experts Exchange can do for you.

Got a question?

We've got the answer.

Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.

Screenshot of Experts Exchange Knowledgebase

Need individual assistance?

Our experts are ready to help.

If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.

Screenshot of Experts Exchange Knowledgebase

Want to learn from the best?

Read articles from industry experts.

Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.

Screenshot of an Article

Working on a long term project?

Store your work and research.

Save solutions to your questions, answers you’ve discovered through searching plus helpful articles in your personal knowledgebase for easy future access.

Screenshot of Experts Exchange Knowledgebase

Access the answers to your technology questions today.

Subscribe Now

30-day free trial. Register in 60 seconds.

What Makes Experts Exchange Unique?

Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Trusted by the world's most respected brands.

image of each brand's logo

Faithfully serving IT professionals since 1996.

Experts Exchange Logo

Try it out and discover for yourself.

Subscribe Now

30-day free trial. Register in 60 seconds.

Related Solutions

  1. IPsec VPN
    I wonder if there is a free or cheap stable IPsec based VPN that has the following characteristicas: -It supports Linux and Windows XP -It can be configured to connect directly host to host -There exist high-end VPN concentrator hardware that can handle requests on the serve...
  2. IPSec VPN
    Trying to setup new ASA box for IPSec VPN. I receive this error message in ASDM when a VPN client tries to connect. Group = DefaultRAGroup, IP = x.x.x.x, Error: Unable to remove PeerTblEntry Group = DefaultRAGroup, IP = x.x.x.x, Removing peer from peer table failed, no ma...
  3. CISCO 1700 series IPSEC VPN setup
    Hi, I have a cisco 1750 router, running 12.3 IOS advanced security. I need to setup a IPSEC remote access vpn so that clients can dial in to the office. They will be using the cisco vpn client for windows. Can someone give me a link that pertains to IPSEC vpn ?
  4. Cisco IPSEC vpn
    I am planning to setup a cisco ipsec vpn. Does a windows certificate server need to be installed on the domain or can cisco device itself provide the certificate to remote access clients ? The cisco device is cisco 1700 with advanced security IOS
  5. IPSEC VPN
    I am having trouble getting a VPN connection established. I have 2 ZyWALL 70 firewalls with latest firmware at 2 different locations. I have tried several different configurations and I can get phase 1 working but phase 2 gives me errors which I will post in the code sectio...
  6. IPSec
    What are the advantages and disadvantages of implementing IPSec using these methods: 1. Gateway to Gateway (using Firewall features) 2. Gateway to Gateway (using Router) 3a. Host to host (tunnel mode) 3b. Host to host (transport mode) Is it true that IPSec theory host to ho...

Free Tech Articles

  1. WARNING: 5 Reasons why you should NEVER fix a computer for free.
    It is in our nature to love the puzzle. We are obsessed. The lot of us. We love puzzles. We love the challenge. We thrive on finding the answer. We hate disarray. It bothers us deep in our soul. W...
  2. SCCM OSD Basic troubleshooting
    SCCM 2007 OSD is a fantastic way to deploy operating systems, however, like most things SCCM issues can sometimes be difficult to resolve due to the sheer volume of logs to sift through and the dispe...
  3. Migrate Small Business Server 2003 to Exchange 2010 and Windows 2008 R2
    This guide is intended to provide step by step instructions on how to migrate from Small Business Server 2003 to Windows 2008 R2 with Exchange 2010. For this migration to work you will need the fo...
  4. Create a Win7 Gadget
    This article shows you how to create a simple "Gadget" -- a sort of mini-application supported by Windows 7 and Vista. Gadgets can be dropped anywhere on the desktop to provide instant information, ...
  5. Outlook continually prompting for username and password
    There have been a lot of questions recently regarding Outlook prompting for a username and password whilst using Exchange 2007. There are a few reasons why this would happen and I will try to cover t...
  6. Backup Exchange 2010 Information Store using Windows Backup
    There seems to be quite a lot of confusion around the ability to backup Exchange 2010 using the built in Windows Backup feature. This stems from the omission of this feature prior to Exchange 2007 s...

Cloud Class Webinars

  1. Avoiding Bugs in Microsoft Access
    Alison Balter takes and in-depth look at avoiding bugs in Access. In this webinar you will learn about using the immediate window to debug your applications, invoking the debugger, using breakpoints to troubleshoot, stepping through code, setting the next statement to execute, ...
  2. Top 10 Best New Features in Visio 2010
    Scott Helmers gives live demonstrations of the top 10 new features in Visio 2010. This webinar will teach you how to create compelling diagrams by adding shapes to the page with a single click, linking the shapes in a diagram to data in Excel (or SQL Server, or SharePoint), ...
  3. IT Consultant Business Secrets Revealed
    Michael Munger, Experts Exchange tech pro and IT consultant, pulls back the curtain on his very successful businesses and answers question on every IT consultant and business owner should know about. He shares secrets on what he did to solve the 5 most common problems in IT, ...
  4. Disaster Recovery and Business Continuity
    Quest CTO, Mike Billon, gives an overview of the steps involved in building a dunamic disaster recovery plan. Through case studies and an examination of software/hardware tooles for monitoring and testing, you'll gain a better understandin of where you are, where you want ...
  5. Organize Your Visio Diagrams with Containers and Lists
    Scott Helmers uses cross functional flowcharts, wireframe diagrams, data graphic legends and seating charts to teach you: how to ustilize all three new structured diagram components in Visio 2010, the best practices for organizeing shapes in previous version of Visio, how to organize ...
  6. How to Us Objects, Properties, Events and Methods in Microsoft Access
    Alison Dalter gives an in-depbth look at objects, properties, events and methods in Microsoft Access. In this webinar you will learn about using the object browser, referring to objects, working with properties and methods, working with object variables, understanding the ...

Join the Community

Give a Little. Get a Lot.

Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.

Join the Community

Answers

 

by: deimarkPosted on 2009-08-01 at 11:06:47ID: 24996124

From the Juniper side, have a look at http://kb.juniper.net/kb/documents/public/resolution_path/J_FW_VPN_Config_or_Trblsh.htm

This will give an idea on how to set up the VPN itself.

Bear in mind that there are 2 types of site to site VN ont eh Juniper, route based and policy based.  Policy based uses the policy to encrypt and route based will create a tunnel interface and you route the VPN traffic to the tunnel interface

With regards to the cisco, I have to defer to another expert.

Caveats I have seen with VPNs from Juniper to 3rd party devices, is that the Juniper tends to be quite strict on what it will accept as VPN credentials, so if it does not come up 1st time after configuring it, then double check that all the phase 1 and 2 credentials n each side match exactly.

HTH

 

by: lrmoorePosted on 2009-08-01 at 18:44:41ID: 24997441

 

by: shwaqar82Posted on 2009-08-01 at 19:11:28ID: 24997489

Irmoore,
the link you have given talks about configuration of ipsec between pix and netscreen
In my case i just have netscreen and juniper or cisco routers.
So can i use them instead of pix?
What configuration changes i will have to make if i use a router instead of pix firewall?
Please i would really appreciate if you could exactly tell me what changes should be made
Do you think it would be more easier to have a ipsec between netscreen and juniper router than to have between netscreen and cisco router?

 

by: shwaqar82Posted on 2009-08-01 at 19:13:28ID: 24997494

Deimark,
Thanks for the link but the link you gave me, i saw some configuration examples but they require login.
Should i make an account over there? is it free?
is there a way to access the information without login?

 

by: shwaqar82Posted on 2009-08-01 at 19:29:36ID: 24997531

Could someone kindly give me a configuration example of how to configure policy based ipsec vpn between juniper router and netscreen firewall?
OR
between cisco router and netscreen
OR
both
Is policy based vpn simpler than route based vpn?
i want use easy and simple method.
Plus, how can i check the version of my ScreenOS?

 

by: deimarkPosted on 2009-08-02 at 08:50:58ID: 24999191

For version of screenos, run a "get sys" the version of screenos will be there.

With regards to the examples:

http://kb.juniper.net/KB8554

This requires no login as far as I can see bud.

Can you confirm which one you don't have access to?

 

by: lrmoorePosted on 2009-08-02 at 10:27:58ID: 24999550

It is the same configuration on the Netscreen. Use the IOS router configuration in this example of a router to PIX. The router config is the same if going to a Netscreen
http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a0080094498.shtml

 

by: shwaqar82Posted on 2009-08-02 at 15:37:25ID: 25000908

deimark,
i cant access KB 3715 ( ipsec between juniper j series router and Netscreen), it requires login
and thats the document i m looking for

 

by: shwaqar82Posted on 2009-08-02 at 15:59:55ID: 25000990

Irmoore,
thanks for the link
so you mean i should have the netscreen configuration from the previous link and use the configuration of router from the second link you gave me? thats what you mean?
One more thing, this nat thing confuses me...the link u gave has nat and route-map and nat pool...
all this confuses me...i just want a simple ipsec.  Can i omit those nat parts in the configuration?
Can you tell me the configuration example you gave me of Netscreen in the previous link...is it policy based or route based?

 

by: lrmoorePosted on 2009-08-02 at 16:21:12ID: 25001065

I would assume the Netscreen config is policy based because that is what the Cisco side is.
Yes, use the Netscreen config from the first link, and the Cisco router config from the second like.
I can only assume that you are already Natting on the Cisco router. If yes, then you have to do the route-map thing. If not, then you do not. Can you post that config?

 

by: shwaqar82Posted on 2009-08-02 at 18:42:49ID: 25001484

Acually my confusion is almost gone as i have found out the way to configure IPsec between Netscreen and Cisco router., at least theoretically, i still have to configure it to see if it works 100%
Now my next target is to implement ipsec between Netscreen and Juniper router.
Actually my ultimate objective is to implement hub and spoke ipsec VPN...with netscreen acting as a hub, Cisco router and Juniper router as spokes. Thats why i m first trying simple things first then go for the hub and spoke.
I am attaching a diagram which show what i m trying to achieve...can you guys tell me if its coceptually correct. Plus, would it be better or easier if i implement GRE tunnel along with ipsec? CAn GRE tunnels be configured in Netscreen? and most importantly, Can someone please give me a configuration example of Hub and Spoke VPN using Netscreen as hub and juniper or cisco router as spokes.?
Can Hub and spoke IPSEc VPN be implemented without the use of GRE tunnels?
One more thing, ethernet2 of netscreen is by default in DMZ zone...so i can set it to untrust zone as per my diagram?

Thanks,

 

by: lrmoorePosted on 2009-08-02 at 20:12:45ID: 25001698

Let's get the first part taken care of. It's not right to morph a question in the middle of a thread. We want to keep a clean database of 1 question/1 answer.
Most of the issues you face will depend on the NetScreen side. Unfortunately, we don't have many NetScreen or juniper experts on this site.

 

by: shwaqar82Posted on 2009-08-02 at 21:18:37ID: 25001847

So you mean i should stop asking questions related to juniper or netscreen because you guys wont be able to help much?

 

by: shwaqar82Posted on 2009-08-02 at 21:23:41ID: 25001858

Ok this is a pretty simple question:
I have a netscreen firewall and a cisco router.
I have set the ethernet interface of the netscreen and put the ip address as 2.2.2.2/30
and on cisco ethernet interface i have put 2.2.2.1/30
When I try to ping from netscreen to cisco, it pings but when i ping from cisco to netscreen it doesnt.
by the way, that interface is untrust interface of netscreen.
So that means inbound traffic is blocked but outboud traffic is allowed in the netscreen.(maybe thats the default in netscreen)
Can you tell me how can i allow inbound traffic to flow in netscreen?

 

by: deimarkPosted on 2009-08-03 at 01:32:43ID: 25002624

I will answer inline bud (I am a junoper bod, BTW :P)

Ok this is a pretty simple question:
I have a netscreen firewall and a cisco router.
I have set the ethernet interface of the netscreen and put the ip address as 2.2.2.2/30
and on cisco ethernet interface i have put 2.2.2.1/30

>>  All fine so far :D

When I try to ping from netscreen to cisco, it pings but when i ping from cisco to netscreen it doesnt.
by the way, that interface is untrust interface of netscreen.

>> By default, the untrust interfaces on a netscreen BLOCK PINGs to the interface.  This is separate form the policies, so does not indicate its blocking all traffic,

>> To allow pings tpo your external interface type in the following:
    set int e<whatever your ext interface is> manage ping

I would not recommend having this enabled permanently.  To un set, type "un" berfore the set.

So that means inbound traffic is blocked but outboud traffic is allowed in the netscreen.(maybe thats the default in netscreen)

>>  As above, the blocked ping is not indicative of blocking all traffic.

Can you tell me how can i allow inbound traffic to flow in netscreen?

>>  Create a policy to allow the specific traffic.  It really is that simple bud.

>>  If the traffic is still being dropped, you can run debugs to see what is going on and why the traffic is being blocked and what we can do about it.

Does this answer your question?

 

by: lrmoorePosted on 2009-08-03 at 04:18:58ID: 25003339

>So you mean i should stop asking questions related to juniper or netscreen because you guys wont be able to help much
Not at all. I mean we should keep this thread to the original question and not morp it into something different, much more complicated.

@ deimark - glad to have you around!

 

by: shwaqar82Posted on 2009-08-03 at 17:18:01ID: 25009607

Deimark and Irmoore thanks for the replies guys.
Deimark, I tried your command and now its pinging, thanks a lot
Can someone give me a sample configuration for juniper router (Jseries) to juniper router ipsec vpn?
It would be nice if there is a diagram as well so that i can better understand the configuration.
My problem is that i found couple of configuration for ipsec between juniper routers but they are without any diagram due to which i have trouble understanding whats going on.
Please guys i really need your help...
If you find a sample configuration then please include diagram and if there isnt then i would really appreciate if you could draw the diagram according to the config so that i can understand it better.
Please note that i have a J series router
Deimark, you seem to be an expert on Juniper so i really need your help in this one bud.

Thanks,

 

by: deimarkPosted on 2009-08-04 at 00:30:59ID: 25011298

http://kb.juniper.net/kb/documents/public/resolution_path/J_visio_JSeries_VPN_Config_or_Trblsh.htm

Gives example info and instructions on J series VPNs bud.  If the PDF page does not open, then "download the link as" and it will save fine

 

by: shwaqar82Posted on 2009-08-04 at 03:46:15ID: 25012154

Thanks a lot Deimark for the link. It really helped me understand the concept however, the configuration example is between juniper and netscreen only. Can you give me any configuration example of ipsec between juniper to juniper router with a network diagram?
Also i would be very thankful if you can find out a hub and spoke vpn config example with diagram where  netscreen and juniper or cisco routers are involved. I have found few configs but it only involved netscreen. I just have one netscreen firewall

Thanks,

 

by: deimarkPosted on 2009-08-04 at 03:56:39ID: 25012223

The same principles apply here bud, no matter what the device is.

If you have a look at the PDF in http://kb.juniper.net/kb/documents/public/junos/jsrx/JSeries_SRXSeries_Route-based_VPN_to_ScreenOS_v13.pdf

This has the route based VPN info there for you, with the example using a J series and SSG5.

We can replace the SSG5 with another J series and follow the same process as configuring the original J series box, we just replace the networks and IPs used to be the ones assigned to the SSG

ie J series 1 will have external IP of 1.1.1.2/30 with protected LAN of 10.10.10.0/24
J series 2 will have external IP of 2.2.2.2/30 with protected LAN of 192.168.168.0/24

For hub and spoke, its all fairly similar.  The branches will all have a single VPN configured to the hub, with appropriate routing etc Iie if it needs to talk to another branches LAN, it has a route to send them down the tunnel to the hub which will then route onwards to correct tunnel/endpoint)

The hub with a VPN to each branch with appropriate routing also.  As long as there are valid routes and the traffic has a policy to allow it, it all should work fine.

Junipers NSM takes a lot of the pain out of the VPN config by using a nice GUI to create the topology and set the VPN parameters, which will then convert to CLI commands and send onto the devices

Does this help any?

DM

 

by: shwaqar82Posted on 2009-08-06 at 17:46:06ID: 25039245

Thanks a lot Deimark!
i really appreciate your answer and explanation.
Now my final task is to use netscreen as a firewall with static NAT and configure multiple zones i.e trust, untrust and DMZ. Can you suggest me a simple network diagram to accomplish this?
For example, I can put 2 or 3 routers and use netscreen as a firewall between them and do static NAT.
Can you give me a link for sample configuration of the above mentioned objective, so that i can understand how i can implement such a thing using netscreen as a firewall.
Is static NAT in netscreen is called Mapped IP (MIP)?

Thanks,

 

by: deimarkPosted on 2009-08-07 at 00:25:34ID: 25040493

There are quite a few different types of NAT that Screenos can do bud but in essence, what you are looking to do should be able to get done using one or 2 of the methods.

However, in the interests of keeping EE in the premise of 1 question 1 answer for better searching I think it would be better if you closed this question off and asked a new one.

I can then have a wee look at the new question re nat.

Does this help?

 

by: shwaqar82Posted on 2009-08-07 at 03:28:24ID: 25041333

ok i will close this question off
Thanks once again for all the answers

 

by: deimarkPosted on 2009-08-07 at 03:32:25ID: 25041355

cheers bud :D

20120131-EE-VQP-002

3 Ways to Join

30-Day Free Trial

The Experts

98% positive feedback on 31,087 answers since March 2000. angeliii is a Microsoft Most Valuable Professional for his work with MS SQL Server & Develoment.

He has also proven his knowledge of Visual Basic Programming, PHP Scripting and Oracle Databases.

The Experts

97% positive feedback on 10,752 answers since July 2000. lrmoore has more than 18 years experience in the networking industry.

The six-time Mircosoft MVPs specialties include firewalls, virtual private networking, and network management.

Testimonials

"...and excellent source for support... Kind of like having your very own IT dept." Electriciansnet

Testimonials

"I was apprehensive at signing up at first. However... it has already made my life as an IT administrator much easier." JaCrews

Testimonials

"WOW! You guys have great, active, and knowledgeable people on here." moore50

Business Clients

Business Clients

In the Press

"If you’ve got a question... Experts Exchange can supply an answer.”

In the Press

"...an invaluable aid for both IT professionals and those who require tech support."

In the Press

"where IT professionals provide quick answers on just about any topic"

Business Account Plans

Loading Advertisement...