Solved

Create point to point VPN connection

Posted on 2008-10-02
3
868 Views
Last Modified: 2008-12-31
I need to create a site to site VPN connection to carry email traffic between a satellite office to the main office using Juniper SSG5 firewall.  There are a couple of things that I want to achieve:
The public address of the satellite office Juniper is 12.2.x.x. // the LAN address is 192.168.50.1
The public address of the main office Juniper is 130.182.x.x
Things I want to achieve:
1)  Create a login script at the domain controller that would run at login and would create a route on the workstation directing any traffic for email to the 192.168.50.1
2)  Create a constant always on connection between the 2 firewalls.  
Any suggestions to achieve this easily would be greatly appreciated.
0
Comment
Question by:LSugita
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 63

Expert Comment

by:SysExpert
ID: 22627665
The Juniper site has docs
KB8533  is a good start

Their site has issues some time accessing the KB DB though.

I hope this helps !
0
 
LVL 3

Accepted Solution

by:
tismetoo earned 500 total points
ID: 22650815
Two aspects:
The route can be dealt with in 2 ways. Personally I woiudl put the route on the default gateway, which is presumably the Netscreen anyway. The other option is to use the "route add" command with the -p switch to make it permanent so you don't have to use the login script.
The always on connection on the Netscreen can be acheived with the "VPN Monitor" setting on the Autokey IKE portion of the VPN config.
Personally I would configure a route based VPN, with these rough steps:

Define tunnel interface
Define routes
Configure Phase 1 settings ( vpn gateway )
Configure Phase 2 settings ( Autokey IKE )
Define address objects for each site
Configure policies.

Good documentation and examples are available from Juniper:
http://www.juniper.net/techpubs/software/screenos/screenos6.1.0/index.html
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
pfsense upgrade from 2.2.6 to 2.3.3 28 92
Cisco ASA 5510 Question 3 49
DNS issue. Can't add a server to a domain 23 207
DNS and Promoting Server 2012R2 to DC Issues 10 49
This article explains how to install and use the NTBackup utility that comes with Windows Server.
I was prompted to write this article after the recent World-Wide Ransomware outbreak. For years now, System Administrators around the world have used the excuse of "Waiting a Bit" before applying Security Patch Updates. This type of reasoning to me …
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

752 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question