Solved

Configuring Windows VPN through Juniper SSG-5 firewall

Posted on 2011-02-25
6
1,676 Views
Last Modified: 2012-05-11
Ok, here's what I have going on.

I'm a Juniper noob and was hoping someone here could show me the error of my ways.  Here is my situation:

I have a Juniper SSG-5 firewall with one static IP going through interface 0/0.  I need to open up the Windows VPN port (1723) to IP 192.168.3.10 in my network. What I did so far was go to that interface and to VIP and created a new virtual port (1723) and created a service pointing to 1723 and the server IP is the address of the windows server which is the vpn server.

Then I went to polices and created a policy from Untrust to Trust ; Source - Any ; Destination - VIP (0/0) ; and the services are PPTP and GRE.  

I ran a port check and the port is accessible from the internet but my VPN won't connect.  Am I missing anything?
0
Comment
Question by:AremP
  • 2
  • 2
6 Comments
 
LVL 32

Accepted Solution

by:
dpk_wal earned 250 total points
ID: 34985870
What you did is right; have a look at article below and configure and advice on results:
http://kb.juniper.net/InfoCenter/index?page=content&id=KB5471

Thank you.
0
 
LVL 69

Assisted Solution

by:Qlemo
Qlemo earned 250 total points
ID: 34993274
As you can see from the link provided above, GRE is not forwarded with your config - and that is the issue. Hence the article recommends to create a custom service containing both the PPTP and GRE definition, and use that as VIP service.
0
 

Author Comment

by:AremP
ID: 35285410
i figured it out
0
 

Author Comment

by:AremP
ID: 35285455
i figured it out
0
 
LVL 69

Expert Comment

by:Qlemo
ID: 35286885
Objection: Invalid reason, and that post cannot be accepted because it contains no solution.

Either we have helped you in "figuring out" - then you need to accept one or more posts,
or you have figured it out without help, then post the solution and accept that.

If you do not post the solution, and none of the posts here helped, then delete the question.
0

Featured Post

Announcing the Most Valuable Experts of 2016

MVEs are more concerned with the satisfaction of those they help than with the considerable points they can earn. They are the types of people you feel privileged to call colleagues. Join us in honoring this amazing group of Experts.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

OpenVPN is a great open source VPN server that is capable of providing quick and easy VPN access to your network on the cheap.  By default the software is configured to allow open access to your network.  But what if you want to restrict users to on…
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question