Device Level VPN Types and Supported Configurations Overview
Table 52: Device-Level VPN Types
Device-Level VPN
Types
Description
AutoKey IKE VPN
Connect devices and/or protected resources. An AutoKey IKE VPN supports mixed-mode, policy-based,
and routing-based VPNs, but does not support RAS users. For details on each step, see "Device Level
AutoKey IKE VPN: Using Gateway Configuration Overview" on page 221.
Manual Key IKE VPNs
Authenticate devices, protected resources, and RAS users in the VPN with manual keys. For details
on each step, see "Device-Level Manual Key VPN: Using XAuth Users Overview" on page 231.
L2TP RAS VPN
Connect L2TP RAS users and protected resources with authentication but without encryption. For
details on each step, see "Device Level Manual Key VPN: Using VPN Rule Configuration Overview"
on page 234.
L2TP-over-AutoKey IKE
Connect L2TP RAS users and protected resources. An L2TP-over-AutoKey IKE RAS VPN supports
RAS VPN
policy-based VPNs and L2TP RAS users, but does not support routing-based VPNs. For details on
each step, see "Creating Device Level L2TP-over-Autokey IKE VPNs Overview" on page 237.
Related
Documentation
Device Level AutoKey IKE VPN: Using Gateway Configuration Overview
Copyright © 2010, Juniper Networks, Inc.
You can create four types of device-level VPNs. Table 52 on page 221 describes the types
of device-level VPNs:
Creating device-level AutoKey IKE VPNs is a four stage process:
Supported Configurations
IKE VPNs support tunnel mode, and can be policy-based or route-based; however,
route-based VPNs do not support RAS users.
L2TP VPNs support transport mode and can be policy-based.
Device Level AutoKey IKE VPN: Using Gateway Configuration Overview on page 221
Device Level AutoKey IKE VPN: Using Routes Configuration Overview on page 227
Device-Level AutoKey IKE VPN: Using VPN Configuration Overview on page 227
Creating device-level AutoKey IKE VPNs is a four stage process.
Configure Gateway
Configure Routes (Route-based only)
Configure VPN on the Device
Add VPN rules to Security Policy
A gateway is an interface on your security device that sends and receives traffic; a remote
gateway is an interface on another device that handles traffic for that device. Each security
Chapter 8: Configuring VPNs
221
Need help?
Do you have a question about the NETWORK AND SECURITY MANAGER 2010.4 - CONFIGURING SCREENOS DEVICES GUIDE REV 01 and is the answer not in the manual?