Solved

Configuring Windows VPN through Juniper SSG-5 firewall

Posted on 2011-02-25
6
1,692 Views
Last Modified: 2012-05-11
Ok, here's what I have going on.

I'm a Juniper noob and was hoping someone here could show me the error of my ways.  Here is my situation:

I have a Juniper SSG-5 firewall with one static IP going through interface 0/0.  I need to open up the Windows VPN port (1723) to IP 192.168.3.10 in my network. What I did so far was go to that interface and to VIP and created a new virtual port (1723) and created a service pointing to 1723 and the server IP is the address of the windows server which is the vpn server.

Then I went to polices and created a policy from Untrust to Trust ; Source - Any ; Destination - VIP (0/0) ; and the services are PPTP and GRE.  

I ran a port check and the port is accessible from the internet but my VPN won't connect.  Am I missing anything?
0
Comment
Question by:AremP
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
6 Comments
 
LVL 32

Accepted Solution

by:
dpk_wal earned 250 total points
ID: 34985870
What you did is right; have a look at article below and configure and advice on results:
http://kb.juniper.net/InfoCenter/index?page=content&id=KB5471

Thank you.
0
 
LVL 70

Assisted Solution

by:Qlemo
Qlemo earned 250 total points
ID: 34993274
As you can see from the link provided above, GRE is not forwarded with your config - and that is the issue. Hence the article recommends to create a custom service containing both the PPTP and GRE definition, and use that as VIP service.
0
 

Author Comment

by:AremP
ID: 35285410
i figured it out
0
 

Author Comment

by:AremP
ID: 35285455
i figured it out
0
 
LVL 70

Expert Comment

by:Qlemo
ID: 35286885
Objection: Invalid reason, and that post cannot be accepted because it contains no solution.

Either we have helped you in "figuring out" - then you need to accept one or more posts,
or you have figured it out without help, then post the solution and accept that.

If you do not post the solution, and none of the posts here helped, then delete the question.
0

Featured Post

Retailers - Is your network secure?

With the prevalence of social media & networking tools, for retailers, reputation is critical. Have you considered the impact your network security could have in your customer's experience? Learn more in our Retail Security Resource Kit Today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Windows 10 is mostly good. However the one thing that annoys me is how many clicks you have to do to dial a VPN connection. You have to go to settings from the start menu, (2 clicks), Network and Internet (1 click), Click VPN (another click) then fi…

729 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question