Creating Device-Level Vpns - Juniper NETWORK AND SECURITY MANAGER 2010.3 - ADMINISTRATION GUIDE REV1 Administration Manual

Table of Contents

Advertisement

Network and Security Manager Administration Guide

Creating Device-Level VPNs

592
and gateway, you can override this setting to include only the Reseller external
user group.
In the Security tab, enter the preshared key value (netscreen4), then click Generate
Key.
For Phase 1 Proposals, select User-Defined, then click the Add/Edit icon to add
the pre-g2-3des-sha proposal.
Click OK to save your changes to the gateway.
Click Save to save your configuration changes to the VPN and autogenerate the
policy rules.
To view the autogenerated rules, click the Policy Rules link in the Overrides section.
VPN Manager generates the rules.
Configure Overrides. By default, the gateway attempts to authenticate all users using
7.
the specified authentication server (radius1). You must override the gateway security
settings to enable the VPN to authenticate only the Reseller external user group:
In the overrides area, click the Device Configuration link.
In the navigation tree, double-click Bozeman and select Gateway. The
autogenerated gateway for the Bozeman appears in the main display area.
Right-click the autogenerated gateway and select Edit. The Properties tab appears.
In the IKE IDs/XAuth tab, configure the XAuth area to authenticate only the Reseller
external group.
For user, select User Group.
For User Group, select xa-grp2.
Click OK to save your overrides.
Add the VPN Link. You can create a VPN link between the security policy and the
8.
VPN Manager autogenerated rules. You create this link by inserting a VPN link in the
security policy; this links points to the VPN rules that exist in the VPN Manager.
In Security Policies, select an existing security policy (or create a new security
policy). Right-click and select Add VPN link.
Select the Reseller Remote Access VPN.
Click OK to add the link to the policy.
By default, the link appears at the top of the policy, but you can move the VPN link
anywhere in the policy, just as you would a firewall rule.
You can create four types of device-level VPNs:
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Network and security manager 2010.3

Table of Contents