NetScreen Client VPN Configure
DComTalk.com Forum Index DComTalk.com
Discussion of VoIP, VPN, Video Conferencen, DSL and other data commucations.
 
 FAQFAQ   MemberlistMemberlist     RegisterRegister 
 ProfileProfile   Log in to check your private messagesLog in to check your private messages   Log inLog in 
 
Google
 
Web dcomtalk.com
NetScreen Client VPN Configure

 
Post new topic   Reply to topic    DComTalk.com Forum Index -> Firewalls
Author Message
news.iol.ie
Guest





Posted: Sat Nov 26, 2005 4:34 am    Post subject: NetScreen Client VPN Configure Reply with quote

Hi All

Has anyone configure WIndows XP to VPN with a Juniper firewall using not
using Netscreen-remote. In effect just using the XP's built client VPN
features.

Thanks

Stephen
Back to top
Triffid
Guest





Posted: Sat Nov 26, 2005 9:22 am    Post subject: Re: NetScreen Client VPN Configure Reply with quote

news.iol.ie wrote:

Quote:
Hi All

Has anyone configure WIndows XP to VPN with a Juniper firewall using not
using Netscreen-remote. In effect just using the XP's built client VPN
features.

Thanks

Stephen

Yes, it's possible. I have it working - but it was a PITA, mostly
because XP uses it's own terminology and hides anything that might be
useful for diagnostics.

I expect it would be easier if the client had a static IP, but when the
client IP is dynamic you _must_ use certificates for IKE authentication.
I used OpenSSL as my CA.

Sorry, I can't give you the recipe - I spent hours of trial and error
getting it to work, my notes are messy, and I don't have time to repeat
the process and document it. However, if you have questions along the
way I'll try to help - especially if you document the recipe :-)

Googling 'openssl netscreen' will help too.

Triffid
Back to top
Stephen
Guest





Posted: Sat Nov 26, 2005 5:21 pm    Post subject: Re: NetScreen Client VPN Configure Reply with quote

Triffid wrote:
Quote:


news.iol.ie wrote:

Hi All

Has anyone configure WIndows XP to VPN with a Juniper firewall using
not using Netscreen-remote. In effect just using the XP's built
client VPN features.

Thanks

Stephen


Yes, it's possible. I have it working - but it was a PITA, mostly
because XP uses it's own terminology and hides anything that might be
useful for diagnostics.

I expect it would be easier if the client had a static IP, but when the
client IP is dynamic you _must_ use certificates for IKE authentication.
I used OpenSSL as my CA.

Sorry, I can't give you the recipe - I spent hours of trial and error
getting it to work, my notes are messy, and I don't have time to repeat
the process and document it. However, if you have questions along the
way I'll try to help - especially if you document the recipe :-)

Googling 'openssl netscreen' will help too.

Triffid
Hi


Yes I will document this as I go. Did you use an autokey (IKE) or did
you use L2TP?

Regards

Stephen
Back to top
Triffid
Guest





Posted: Sat Nov 26, 2005 5:21 pm    Post subject: Re: NetScreen Client VPN Configure Reply with quote

Stephen wrote:
Quote:
Triffid wrote:



news.iol.ie wrote:

Hi All

Has anyone configure WIndows XP to VPN with a Juniper firewall using
not using Netscreen-remote. In effect just using the XP's built
client VPN features.

Thanks

Stephen



Yes, it's possible. I have it working - but it was a PITA, mostly
because XP uses it's own terminology and hides anything that might be
useful for diagnostics.

I expect it would be easier if the client had a static IP, but when
the client IP is dynamic you _must_ use certificates for IKE
authentication. I used OpenSSL as my CA.

Sorry, I can't give you the recipe - I spent hours of trial and error
getting it to work, my notes are messy, and I don't have time to
repeat the process and document it. However, if you have questions
along the way I'll try to help - especially if you document the recipe
:-)

Googling 'openssl netscreen' will help too.

Triffid

Hi

Yes I will document this as I go. Did you use an autokey (IKE) or did
you use L2TP?

Regards

Stephen

AutoKey IKE with Dialup as the remote gateway type.

Triffid
Back to top
 
Post new topic   Reply to topic    DComTalk.com Forum Index -> Firewalls All times are GMT
Page 1 of 1

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum




VoIP Solutions: Telephone Systems Electronics Satellite TV Tech & Gadgets
Powered by phpBB