SRX

 View Only
last person joined: yesterday 

Ask questions and share experiences about the SRX Series, vSRX, and cSRX.
Expand all | Collapse all
  • 1.  Dialup VPN

    Posted 10-28-2009 02:41

    Dear folks

     

    Does SRX has the capability of terminating dialup VPN?? is NS-remote used as a client or any other client??

     

    Urgent response is appreciatible.

     

    regards, 



  • 2.  RE: Dialup VPN
    Best Answer

    Posted 10-28-2009 02:47

    Ok just gone through SRX- Security- config guide. Yes this has support via NSR.

     

    any one who has any comment further, can share.

     

    thanks



  • 3.  RE: Dialup VPN

    Posted 10-28-2009 02:49

    Hi,

     

    NS-Remote is not officially supported any more on SRX. But I have a working solution for dialup VPN. It is still working, it's IPSec, isn't it?

     

    If you want to, I will provide you with my config example. Give me an email address or another ressource to

    to upload a simple text-file. I would not like to present the solution here, because Juniper does not support it.

     

    [EDIT]

    http://kb.juniper.net/index?page=content&id=KB14370&actp=search&searchid=1256727835504

     

    Regards,

     

    Klaus



  • 4.  RE: Dialup VPN

    Posted 11-05-2009 06:55

    I would very much like to see how to set up a dial-up vpn using a third party client.  Plese send it to daniel.wells@mhtn.com.



  • 5.  RE: Dialup VPN

    Posted 11-12-2009 01:26

    Hi,

     

    I would also very appreciate to you if you can share dial up vpn configuration with me, actually I m facing this for very long time and can't get help from any body else
    currently I m using Net screen Remote VPN client with SSG 140, now we have purchased SRX 240H but not able to configure dial VPN with srx, also suggest me, can I use same net screen remote VPN with srx or not.

    Again I m very appreciate to you if you can send me the config, My mail Id is anoop@datasecureindia.com

     

     

    Thanks,

     

    Anoop



  • 6.  RE: Dialup VPN

    Posted 11-13-2009 05:46

    Hi,

     

    I am very appreciate too, if you can send me the config of your srx device für dialup vpn, my mail address is

    ingo@seel.de.

     

    Best regards

    Ingo



  • 7.  RE: Dialup VPN

    Posted 12-16-2009 02:44

    Hi All,

     

    finally I did it myself, it is working fine with Netscreen Remote VPN client. I have tested it in my LAB setup. But Officially it is not support by Juniper so now we are going for Dynamic VPN.

     

    Thanks to all for sharing knowledge over here.

     

     

    Thanks,

     

    Anoop Singh

     



  • 8.  RE: Dialup VPN

    Posted 12-16-2009 04:01

    Hello Anoop-Singh,

     

    Can you post your configuration?

     

    regards.



  • 9.  RE: Dialup VPN

    Posted 12-18-2009 04:25

    Hi Anoop can  post  both your srx  config &   your   psd file from vpn client

     



  • 10.  RE: Dialup VPN

    Posted 12-18-2009 22:44
      |   view attached

    Hi,

     

    Please find it as in attachment. I hope your query will be resolved.

     

     

    Thanks,

     

    Anoop Singh

    Attachment(s)

    txt
    vpn.txt   6 KB 1 version


  • 11.  RE: Dialup VPN

    Posted 12-19-2009 02:09

    Thanks Anoop



  • 12.  RE: Dialup VPN

    Posted 12-20-2009 11:52

    Hi

     

    Can any one guide me how to assign IP address/DNS to Netscreen Remote dialup VPN client on SRX?

     

    Thanks



  • 13.  RE: Dialup VPN

    Posted 12-20-2009 16:27

    I would try to use the VSA Juniper assigned attributes for DNS settings



  • 14.  RE: Dialup VPN

    Posted 12-21-2009 04:15

    Hi

     

    I am using local authenticaiton for dialup vpn users not radius.

     

    Thanks



  • 15.  RE: Dialup VPN

    Posted 12-21-2009 10:24

    hi aeroplane ,  you said that you use local authentication for dial up vpn users ?   are you sure ? as per my knowledge srx doen't support that



  • 16.  RE: Dialup VPN

    Posted 12-23-2009 00:19

    Hi SSHSSH,

     

    Yes, I have also used local authentication. You can see my previous attached config.

     

    Also you can follow this command.

     

     

    set access profile xuth-users authentication-order password
    set access profile xuth-users client "test1@abc.com" firewall-user password "$9$1h9ISevMX-b28Xx-Vb2gTzF/p0"

     

    I hope your query will be resolve.

     

     

    Thanks,

    Anoop Singh



  • 17.  RE: Dialup VPN

    Posted 11-13-2009 15:43

    Hi - as per your Forum post on this issue I would appreciate it if you could send me a copy of your work around for this.

     Thanks!

    kevinjbarker@indeptec.com



  • 18.  RE: Dialup VPN

    Posted 11-19-2009 06:50

    Hi Klaus,

     

    is it possible to send me the working solution for dial-up vpn to ingo@seel.de , please?

     

    Thanks and best regards

    Ingo



  • 19.  RE: Dialup VPN

    Posted 11-25-2009 10:45

    Klaus, My email address is msoho@archertechgroup.com

     

    I would very much appreciate if you could send this config example to me.  Thanks!



  • 20.  RE: Dialup VPN

    Posted 11-26-2009 12:02

    Hi Fahad, 

     

    Can you please send me a sample configuration for this 

     

    Thanks my e-mail is groque@pointfinancials.com 

     

    Cheers 



  • 21.  RE: Dialup VPN

    Posted 12-02-2009 14:33

    I would be glad if someone could send me the configuration

     

    flavio-juniper@zipman.it

     

    Thanks 🙂



  • 22.  RE: Dialup VPN

    Posted 12-02-2009 15:04

    Did anyone ever get it? Why not just post it here?

     

    -Keith



  • 23.  RE: Dialup VPN

    Posted 12-03-2009 10:21

    i didn't get it  😞 



  • 24.  RE: Dialup VPN

    Posted 02-08-2012 18:45

    HI Fahad

     

    Can you send me too?

     

    gsilveriodasilva@gmail.com 

     

    Thanks a lot!



  • 25.  RE: Dialup VPN

    Posted 12-18-2009 15:06

     

    Sample configuration for a "normal" DialUp-VPN:
    
    set access profile dialup authentication-order password
    /* Passwort = User */
    set access profile dialup client klauzi firewall-user password "$9$1M2hyKbwgoaUwY6ApOcS"
    
    set security ike proposal phase1 authentication-method pre-shared-keys
    set security ike proposal phase1 dh-group group2
    set security ike proposal phase1 authentication-algorithm sha1
    set security ike proposal phase1 encryption-algorithm 3des-cbc
    set security ike proposal phase1 lifetime-seconds 300
    (maybe change lifetime?)
    
    set security ike policy dialup mode aggressive
    set security ike policy dialup proposals phase1
    set security ike policy dialup pre-shared-key ascii-text "secrect-key"
    
    set security ike gateway dialup dynamic user-at-hostname "test@entrada.de"
    set security ike gateway dialup dynamic connections-limit 10
    set security ike gateway dialup dynamic ike-user-type shared-ike-id
    set security ike gateway dialup external-interface ge-0/0/0
    set security ike gateway dialup xauth access-profile dialup
    
    set security ipsec proposal phase2 protocol esp
    set security ipsec proposal phase2 authentication-algorithm hmac-sha1-96
    set security ipsec proposal phase2 encryption-algorithm 3des-cbc
    set security ipsec proposal phase2 lifetime-seconds 28800
    (lifetime?)
    
    set security ipsec policy dialup perfect-forward-secrecy keys group2
    set security ipsec policy dialup proposals phase2
    
    set security ipsec vpn dialup ike gateway dialup
    set security ipsec vpn dialup ike ipsec-policy dialup
    
    
    Zone/Interface:
    set interfaces ge-0/0/0 unit 0 family inet address 1.1.1.25/24
    
    set security zones security-zone untrust interfaces ge-0/0/0.0 host-inbound-traffic system-services ping
    set security zones security-zone untrust interfaces ge-0/0/0.0 host-inbound-traffic system-services ike
    
    set security policies from-zone untrust to-zone trust policy dialup match source-address any
    set security policies from-zone untrust to-zone trust policy dialup match destination-address any
    set security policies from-zone untrust to-zone trust policy dialup match application any
    set security policies from-zone untrust to-zone trust policy dialup then permit tunnel ipsec-vpn dialup
    set security policies from-zone untrust to-zone trust policy dialup then log session-init
    
    It looks like it does not matter, if one puts an "any" in the policy, even if the
    client has a specific address/network configured. The proxy-id of the client was
    ignored (in my testing)
    
    
    

     

     



  • 26.  RE: Dialup VPN

    Posted 12-18-2009 19:10

    Hi Entrada, 

     

    Thank you for posting your config. One question if I configure dial up VPN clients do I have the controll to allow them to certain network resources.

     

    For example I want my normal head office employees to not have access to my test servers, is that possible? or do I have to allow them to everything? 

     

     

     

     



  • 27.  RE: Dialup VPN

    Posted 01-24-2010 20:16

    culd you send the sampe config to my email tooo : ade@nec.co.id

     

    many thanks