I need help with a Netscreen NS25.

Oct 25, 2005 2 Replies

I need some help with setting up a subnet and a VPN using a Netscreen ns25, any help would be vastly appreciated.


What help do you need on this? Have you had a look at

formatting link

Log into your support page and download the "Concepts and Examples" guide. It's over 300 pages and leads you through things like that.

In short you will:

  1. Make a remote network address object in the untrust zone
  2. Make a local network address object in the trust zone.
  3. Create matching phase 1 proposals both sides
  4. Create maching phase 2 proposals both sides
  5. Create a trust -> untrust policy from the local to the remote network with Encrypt as the action, bound to your phase 2 from step 3.
  6. Create an untrust -> trust policy from the remote network to the local network with encrypt as the action, bound to the phase 2 from step 3.

That's for policy based. If you want route based...

0,1,2 as above
  1. create an unnumbered tunnel interface
  2. create the phase 2 proposals bound to the tunnel interface created in step 3. Specify proxy ID's of remote and local subnets.
  3. create a route for traffic bound for the remote network exiting on the tunnel.1 interface you created
  4. Create permit and deny policies as desired for traffic going to and from remote and local subnets.

-Russ.

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required