Juniper SSG5 設定 L2TP VPN

Configuring an L2TP over IPSec User on the Juniper Firewall


Step one: Open the WebUI. For an example of how to access the WebUI, consult:KB4060 - Accessing Your NetScreen, SSG, or ISG Firewall Using the WebUI 

Step two: From the ScreenOS options menu, click Objects, select Users, and then click Local.

Image of step two

Step three: Click New.

Image of step three

Step four: From the Edit screen, enter a User Name.

Note: For this example, we entered John Doe

.

Image of step four and five

Step five: Click to select Enable.

Step six: Click to select IKE User.

Image of step six and seven

Step seven: Click to choose Simple Identity or Use Distinguished Name For ID. From IKE Identity, enter an identity name.

Note: For this example, we have selected Simple Identity. From IKE Identity, we have entered jdoe@netscreen.com.

Step eight: Click to select L2TP User. Enter the User Password, and then Confirm Password

.

Image of step eight

Note:  If you would like this user to use specific settings, from L2TP/XAuth Remote Settings, enter WINS, DNS, and select the IP Pool to bind to. Otherwise, use the default settings for L2TP.

Step nine: Click OK.

Image of step nine

 

(2)

  Step one: Open the WebUI. For an example of how to access the WebUI, consult: KB4060 - Accessing Your NetScreen, SSG, or ISG Firewall Using the WebUI

Step two: From the ScreenOS options menu, click Objects, select User Group, and then click Local.
Note that on some newer versions of ScreenOS, the menu options may be Objects > Users > Local Groups.

Image of step two

Step three: Click New.

Image of step three

Step four: From the Edits screen, enter a Group Name.

Note: For this example, we have entered usergroup1

.

Image of step four and five

Step five: Click to select an Available Member, and then click the Add Group Members button.

Note: For this example, we have selected John Doe.

Note: For more information on configuring an L2TP user, go to Configuring an L2TP User on the Juniper Firewall.

Step six: Click OK.

Image of step six

(3)


Step one: Open the WebUI. For an example of how to access the WebUI, consult: KB4060 - Accessing Your NetScreen, SSG, or ISG Firewall Using the WebUI

Step two: From the ScreenOS options menu, click VPNs, select AutoKey Advanced, and then click Gateway

.

Image of step two


Step three: Click New.

Image of step three


Step four: From the Edit screen, enter a Gateway Name. From Security Level, click Custom.

Note: For this example, we entered JohnDoeGate

.

Image of step four and five

Step five: From Remote Gateway Type, click to select Dialup User Group. From the Group drop-down menu, click to select your group.

Note: For this example, we selected usergroup1.

Step six: From the Preshared Key text box, enter a Preshared Key.

Note: For this example, we have entered Password9.

Image of step six

Step seven: From Outgoing Interface, click to select your external interface. Then click Advanced.

Note: For this example, the public external interface is the untrust interface on a 5GT in trust-untrust mode.  

Image of step seven

Step eight: From Phase 1 Proposal drop-down menu, click to choose a proposal.

Note: For this example, we chose pre-g2-des-sha. When choosing the Phase 1 Proposal, you must select pre for the proposal.

Image of step eight and nine

Step nine: From Mode (Initiator), click to select Aggressive.

Step ten: Click Return.

Image of step ten

Step eleven: Click OK

.

Image of step eleven

Step twelve: From the ScreenOS options menu, click VPNs, select AutoKey IKE.

Image of step twelve

Step thirteen: Click New

.

Image of step thirteen

Step fourteen: From VPN Name, enter a VPN Name. Click to select Custom.

Note: For this example, we entered JohnDoeIke.

Image of step fourteen and fifteen

Step fifteen: From the Remote Gateway drop-down menu, click to select a Remote Gateway.

Note: For this example, we chose JohnDoeGate.

Step sixteen: Click Advanced

.

Image of step sixteen

Step seventeen: From User Defined, click to select Custom. From the Phase 2 Proposal drop-down menus, click to choose the Phase 2 Proposal settings.

Note: For this example, we chose nopfs-esp-des-md5, nopfs-esp-3des-md5, nopfs-esp-des-sha, and nopfs-esp-3des-sha.

Image of step seventeen and eighteen

Step eighteen: From Transport Mode, click (For L2TP-over-IPSec only). From Bind to, click None.

Step nineteen: Click Return

.

Image of step nineteen

Step twenty: Click OK.

Image of step twenty

(4)

Open the WebUI. For an example of how to access the WebUI, consult: KB4060 - Accessing Your NetScreen, SSG, or ISG Firewall Using the WebUI

Step two: From the ScreenOS options menu, click Objects, and then click IP Pools.

Image of step two

Step three: Click New

.

Image of step three

Step four: From the Edit screen, enter an IP Pool Name, a Start IP, and an End IP.

Note: For this example, we have chosen an IP Pool Name of global, a Start IP of 10.10.2.100, and an End IP of 10.10.2.180.

Warning: To avoid potential routing problems, make sure the IP Pool is on a different IP Subnet than the Trust Zone.

Image of step four and five

(5)


Step one: Open the WebUI. For an example of how to access the WebUI, consult: KB4060 - Accessing Your NetScreen, SSG, or ISG Firewall Using the WebUI

Step two: From the ScreenOS options menu, click VPNs, select L2TP, and then click Default Settings.

Image of step two

Step three: From the Default Settings screen, from the IP Pool Name drop-down menu, click to select global, and then from the PPP Authentication drop-down menu, click to select CHAP.

Note: For more information on configuring an L2TP IP pool, go to Configuring an L2TP IP Pool on the Juniper Firewall

.

Image of step three and note

Note:DNS Primary Server IP, DNS Secondary Server IP and WINS server setting values are optional, and are not required for the L2TP tunnel to work. If DNS and/or WINS settings are set, they will be pushed down to the L2TP PC client.

Note: For this example, for the DNS Primary Server IP, we have entered 210.11.40.3, and for the DNS Secondary Server IP, we have entered 210.11.50.2.

Step four: Click Apply.

Image of step four

 

(6)

  Step one: Open the WebUI. For an example of how to access the WebUI, consult: KB4060 - Accessing Your NetScreen, SSG, or ISG Firewall Using the WebUI

 Step two: From the ScreenOS options menu, click VPNs, select L2TP, and then click Tunnel

.

Image of step two

Step three: Click New.

Image of step three

Step four: From the Tunnel screen, enter a Name.

Note: For this example, we entered sales_corp.

Image of step four and five

Step five: From the Authentication Server drop-down menu, select Local.

Step six: From the Outgoing Interface drop-down menu, select your external interface from which your L2TP client will be connecting.

Note: For this example, we chose ethernet3. The Outgoing Interface could be either ethernet3 or untrust depending on your Firewall device model.

Image of step six and seven

Step seven: For Peer IP, enter 0.0.0.0.

Note:Host Name and Secret are optional, and are used with a Radius server. Host Name is the name of the computer acting as the L2TP access concentrator (LAC). Secret is a secret shared between the LAC and the L2TP network server (LNS).

Image of step eight and note

Step eight: From Keep Alive, enter a value.

Note: For this example, we have entered 60 (the default). The Keep Alive value is the number of seconds of inactivity before the Juniper Firewall device sends an L2TP hello signal to the LAC.

Step nine: Click OK.

Image of step nine

(7)


Step one: Open the WebUI. For an example of how to access the WebUI, consult: KB4060 - Accessing Your NetScreen, SSG, or ISG Firewall Using the WebUI

Step two: From the ScreenOS options menu, click Policies

.

Image of step two

Step three: From the Policies screen, in the From drop-down menu, select Untrust. From the To drop-down menu, click to select Trust.

Image of step three and four

Step four: Click New.

Step five: From the Policies screen, in Source Address, click to select Address Book. From the Address Book drop-down menu, click to select Dial-Up VPN

.

Image of step five and six

Step six: From Destination Address, click to choose New Address or Address Book.

Note: For this example, we have selected New Address, and have entered 192.168.1.50/24.

Step seven: From the Service drop-down menu, click to select Any, and then from the Action drop-down menu, click to select Tunnel.

Image of step seven

Step eight: From the Tunnel VPN drop-down menu, click to select a VPN.

Note: For this example, we have selected JohnDoeIKE

.

Image of step eight and nine

Step nine: From the L2TP drop-down menu, click to select an L2TP tunnel.

Note: For this example, we have used sales_corp as the tunnel name. For more information on configuring the L2TP VPN tunnel, go to Configuring the L2TP VPN Tunnel on the Juniper Firewall.

Step ten: Click to select Position at Top.

Image of step ten and eleven

 

Step eleven: Click OK.

 

 

(8)


Step one: From the Start menu, click Programs, click NetScreen-Remote, and then click to select Security Policy Editor.

Note: With newer versions of NetScreen-Remote, the start menu may be Juniper Networks > NetScreen-Remote

.

Image of step one

Step two: From the Security Policy Editor, click the Add a new connection icon.

Image of step two

Step three: Enter a name for your new connection.

Note: For this example, we used the default name New Connection.

Image of step three

Step four: From Remote Party Identity and Addressing, in the ID Type drop-down menu, click to select IP Address

.

Image of step four

Step five: Enter the Untrust Interface IP Address of the Juniper Firewall you are trying to reach.

Note: For this example, we used 1.1.1.1 as the Untrust interface IP address.

Image of step five

Step six: From the Protocol drop-down menu, click to select UDP. From the Port drop-down menu, click to select L2TP.

Image of step six

Step seven: Click the + to expand New Connection

.

Image of step seven

Step eight: Click My Identity, and then from the Select Certificate drop-down menu, click to select None.

Image of step eight

Step nine: Click Pre-Shared Key

.

Image of step nine

Step ten: Click Enter Key, and then enter the Pre-Shared Key.

Note: The Pre-Shared Key will need to match the one configured on the Firewall device for this connection.

Image of step ten and eleven

Step eleven: Click OK.

Step twelve: Click Security Policy, and then click to select Aggressive Mode.

Image of step twelve

Step thirteen: Click My Identity

.

Image of step thirteen

Step fourteen: From the ID Type drop-down menu, click to select E-mail Address.

Image of step fourteen and fifteen

Step fifteen: Enter the email address corresponding to the ID.

Note: For this example, we have used jdoe@netscreen.com. This is the IKE user's simple identity and not their username. The E-mail Address can be a username or an actual email address. However, this needs to match the settings on the Juniper Firewall.

Step sixteen: Click the + to expand Security Policy

.

Image of step sixteen

Step seventeen: Click the + to expand Authentication (Phase 1).

Image of step seventeen and eighteen

Step eighteen: Click to select Proposal 1.

Step nineteen: From the Encrypt Alg drop-down menu, click to select encryption type. From the Hash Alg drop-down menu, click to select authentication type.

Note: For this example, we have used DES for Encrypt Alg and SHA-1 for Hash Alg

.

Image of step nineteen and twenty

Step twenty: From the Key Group drop-down menu, click to select Diffie-Hellman Group 2.

Step twenty-one: Click the + to expand Key Exchange (Phase 2).

Image of step twenty-one and twenty-two

Step twenty-two: Click Proposal 1.

Step twenty-three: From the Encrypt Alg drop-down menu, click to select encryption type. From the Hash Alg drop-down menu, click to select authentication type.

 

(9)

  Step one: From the Start menu, select Settings, select Network and Dial-up Connections, and then click Make New Connection.

Note: For Windows XP, goto Control Panel and select Network Connections. Then click Create a new connection

.

Image of step one

Step two: From the Network Connection Wizard, click Next.

Image of step two

Step three: From Network Connection Type, click to select Connect to a private network through the Internet, and then click Next.

Note: For Windows XP, choose Connect to the network at my workplace. Then select Virtual Private Network connection

.

Image of step three

Step four: You may see the Public Network screen at this time. Click to select the dial-up connection that connects you to your ISP. If your physical connection is an Ethernet connection, select Do not dial initial connection. If the physical connection is through an ISP, select Automatically dial this initial connection. Click Next.

Note: For Windows XP, you will be prompted first for a connection name first.

Image of step four

Note: For this example, we used Do not dial the initial connection.

Step five: From Destination Address, in the Host name or IP address box, enter the IP address or hostname of your Juniper Firewall's Untrust interface, and then click Next.

Image of step five

Note: For this example, we have used 1.1.1.1 as the Untrust IP address.

Step six: From Connection Availability, click to select For all users, and then click Next.

Image of step six

Step seven: From the Completing the Network Connection Wizard, enter a connection name, and then click Finish.

Note: For Windows XP, the connection name was entered before step 4.

Image of step seven

Step eight: Click Properties

.

Image of step eight

Step nine: Click to select the Security tab, click to select Advanced (custom settings), and then click Settings.

Image of step nine

Step ten: From Advanced Security Settings, from the Data encryption drop-down menu, click to select Optional encryption (connect even if no encryption)

.

Image of step ten

Step eleven: From Logon security, click to select Allow these protocols. Click to select only Unencrypted password (PAP) and Challenge Handshake Authentication Protocol (CHAP). Click to clear any protocols that do not apply.

Image of step eleven and twelve

Step twelve: Click OK.

Step thirteen: Click to select the Networking tab. From the Type of VPN server I am calling drop-down menu, click to select Layer-2 Tunneling Protocol (L2TP).

Note: For Windows XP, select L2TP IPSec VPN.

Image of step thirteen and fourteen

Step fourteen: Click OK.

Step fifteen: From Network and Dial-up Connections, double-click the Dial-up Connection.

Image of step fifeteen

Step sixteen: Enter your User name and Password.

Note: The User name and Password matches the username and password of the L2TP user configured on the Firewall.

Image of step sixteen and seventeen

Step seventeen: Click Connect.

arrow
arrow
    全站熱搜

    bubble727 發表在 痞客邦 留言(2) 人氣()