Solved

Configuring Windows VPN through Juniper SSG-5 firewall

Posted on 2011-02-25
6
1,656 Views
Last Modified: 2012-05-11
Ok, here's what I have going on.

I'm a Juniper noob and was hoping someone here could show me the error of my ways.  Here is my situation:

I have a Juniper SSG-5 firewall with one static IP going through interface 0/0.  I need to open up the Windows VPN port (1723) to IP 192.168.3.10 in my network. What I did so far was go to that interface and to VIP and created a new virtual port (1723) and created a service pointing to 1723 and the server IP is the address of the windows server which is the vpn server.

Then I went to polices and created a policy from Untrust to Trust ; Source - Any ; Destination - VIP (0/0) ; and the services are PPTP and GRE.  

I ran a port check and the port is accessible from the internet but my VPN won't connect.  Am I missing anything?
0
Comment
Question by:AremP
  • 2
  • 2
6 Comments
 
LVL 32

Accepted Solution

by:
dpk_wal earned 250 total points
ID: 34985870
What you did is right; have a look at article below and configure and advice on results:
http://kb.juniper.net/InfoCenter/index?page=content&id=KB5471

Thank you.
0
 
LVL 68

Assisted Solution

by:Qlemo
Qlemo earned 250 total points
ID: 34993274
As you can see from the link provided above, GRE is not forwarded with your config - and that is the issue. Hence the article recommends to create a custom service containing both the PPTP and GRE definition, and use that as VIP service.
0
 

Author Comment

by:AremP
ID: 35285410
i figured it out
0
 

Author Comment

by:AremP
ID: 35285455
i figured it out
0
 
LVL 68

Expert Comment

by:Qlemo
ID: 35286885
Objection: Invalid reason, and that post cannot be accepted because it contains no solution.

Either we have helped you in "figuring out" - then you need to accept one or more posts,
or you have figured it out without help, then post the solution and accept that.

If you do not post the solution, and none of the posts here helped, then delete the question.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

Suggested Solutions

Juniper VPN devices are a popular alternative to using Cisco products. Last year I needed to set up an international site-to-site VPN over the Internet, but the client had high security requirements -- FIPS 140. What and Why of FIPS 140 Federa…
I've written this article to illustrate how we can implement a Dynamic Multipoint VPN (DMVPN) with both hub and spokes having a dynamically assigned non-broadcast multiple-access (NBMA) network IP (public IP). Here is the basic setup of DMVPN Pha…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now