Solved

Create point to point VPN connection

Posted on 2008-10-02
3
866 Views
Last Modified: 2008-12-31
I need to create a site to site VPN connection to carry email traffic between a satellite office to the main office using Juniper SSG5 firewall.  There are a couple of things that I want to achieve:
The public address of the satellite office Juniper is 12.2.x.x. // the LAN address is 192.168.50.1
The public address of the main office Juniper is 130.182.x.x
Things I want to achieve:
1)  Create a login script at the domain controller that would run at login and would create a route on the workstation directing any traffic for email to the 192.168.50.1
2)  Create a constant always on connection between the 2 firewalls.  
Any suggestions to achieve this easily would be greatly appreciated.
0
Comment
Question by:LSugita
3 Comments
 
LVL 63

Expert Comment

by:SysExpert
ID: 22627665
The Juniper site has docs
KB8533  is a good start

Their site has issues some time accessing the KB DB though.

I hope this helps !
0
 
LVL 3

Accepted Solution

by:
tismetoo earned 500 total points
ID: 22650815
Two aspects:
The route can be dealt with in 2 ways. Personally I woiudl put the route on the default gateway, which is presumably the Netscreen anyway. The other option is to use the "route add" command with the -p switch to make it permanent so you don't have to use the login script.
The always on connection on the Netscreen can be acheived with the "VPN Monitor" setting on the Autokey IKE portion of the VPN config.
Personally I would configure a route based VPN, with these rough steps:

Define tunnel interface
Define routes
Configure Phase 1 settings ( vpn gateway )
Configure Phase 2 settings ( Autokey IKE )
Define address objects for each site
Configure policies.

Good documentation and examples are available from Juniper:
http://www.juniper.net/techpubs/software/screenos/screenos6.1.0/index.html
0

Featured Post

Optimizing Cloud Backup for Low Bandwidth

With cloud storage prices going down a growing number of SMBs start to use it for backup storage. Unfortunately, business data volume rarely fits the average Internet speed. This article provides an overview of main Internet speed challenges and reveals backup best practices.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
This tutorial will walk an individual through configuring a drive on a Windows Server 2008 to perform shadow copies in order to quickly recover deleted files and folders. Click on Start and then select Computer to view the available drives on the se…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question