I need help with a Netscreen NS25.

I need some help with setting up a subnet and a VPN using a Netscreen ns25, any help would be vastly appreciated.

Reply to
gr8is2004
Loading thread data ...

What help do you need on this? Have you had a look at

formatting link

Reply to
andrewmmorris

Log into your support page and download the "Concepts and Examples" guide. It's over 300 pages and leads you through things like that.

In short you will:

  1. Make a remote network address object in the untrust zone
  2. Make a local network address object in the trust zone.
  3. Create matching phase 1 proposals both sides
  4. Create maching phase 2 proposals both sides
  5. Create a trust -> untrust policy from the local to the remote network with Encrypt as the action, bound to your phase 2 from step 3.
  6. Create an untrust -> trust policy from the remote network to the local network with encrypt as the action, bound to the phase 2 from step 3.

That's for policy based. If you want route based...

0,1,2 as above
  1. create an unnumbered tunnel interface
  2. create the phase 2 proposals bound to the tunnel interface created in step 3. Specify proxy ID's of remote and local subnets.
  3. create a route for traffic bound for the remote network exiting on the tunnel.1 interface you created
  4. Create permit and deny policies as desired for traffic going to and from remote and local subnets.

-Russ.

Reply to
Somebody.

Cabling-Design.com Forums website is not affiliated with any of the manufacturers or service providers discussed here. All logos and trade names are the property of their respective owners.