Solved

Create point to point VPN connection

Posted on 2008-10-02
3
864 Views
Last Modified: 2008-12-31
I need to create a site to site VPN connection to carry email traffic between a satellite office to the main office using Juniper SSG5 firewall.  There are a couple of things that I want to achieve:
The public address of the satellite office Juniper is 12.2.x.x. // the LAN address is 192.168.50.1
The public address of the main office Juniper is 130.182.x.x
Things I want to achieve:
1)  Create a login script at the domain controller that would run at login and would create a route on the workstation directing any traffic for email to the 192.168.50.1
2)  Create a constant always on connection between the 2 firewalls.  
Any suggestions to achieve this easily would be greatly appreciated.
0
Comment
Question by:LSugita
3 Comments
 
LVL 63

Expert Comment

by:SysExpert
ID: 22627665
The Juniper site has docs
KB8533  is a good start

Their site has issues some time accessing the KB DB though.

I hope this helps !
0
 
LVL 3

Accepted Solution

by:
tismetoo earned 500 total points
ID: 22650815
Two aspects:
The route can be dealt with in 2 ways. Personally I woiudl put the route on the default gateway, which is presumably the Netscreen anyway. The other option is to use the "route add" command with the -p switch to make it permanent so you don't have to use the login script.
The always on connection on the Netscreen can be acheived with the "VPN Monitor" setting on the Autokey IKE portion of the VPN config.
Personally I would configure a route based VPN, with these rough steps:

Define tunnel interface
Define routes
Configure Phase 1 settings ( vpn gateway )
Configure Phase 2 settings ( Autokey IKE )
Define address objects for each site
Configure policies.

Good documentation and examples are available from Juniper:
http://www.juniper.net/techpubs/software/screenos/screenos6.1.0/index.html
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This is an article about my experiences with remote access to my clients (so that I may serve them) and eventually to my home office system via Radmin Remote Control. I have been using remote access for over 10 years and have been improving my metho…
You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
This tutorial will show how to push an installation of Backup Exec to an additional server in both 2012 and 2014 versions of the software. Click on the Backup Exec button in the upper left corner. From here, select Installation and Licensing, then I…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now